IBM and Red Hat say their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries, including backported fixes intended for software still running in production.
The companies also announced the general availability of Lightwell Clearinghouse, a service that allows enterprise customers to submit specific open source software dependencies for priority review and remediation.
In the announcement, IBM and Red Hat positioned the work as a response to what they describe as an increasing business risk: autonomous AI agents becoming more capable of chaining together multiple lower-severity weaknesses into more serious attacks. The companies argued that vulnerability detection alone does not reduce operational risk if fixes are not available for the versions organisations actually run.
According to the press release, Lightwell is designed to develop version-specific fixes for open source dependencies and deliver them through secured repositories intended to integrate with customers’ existing IT processes. IBM and Red Hat said this approach is aimed at enabling remediation without requiring organisations to replace their existing scanners, repositories, development pipelines or testing processes.
The companies said teams can use the Lightwell Network to access “verified patches” and integrate remediated software into existing workflows, while Clearinghouse provides a mechanism for customers to request priority review, remediation and fixes that can be applied to older software versions.
IBM and Red Hat also said applicable fixes developed through Lightwell are contributed back to upstream open source projects under responsible disclosure protocols, while maintaining embargo protections for Clearinghouse participants.
Gunnar Hellekson, vice president and general manager, Lightwell, Red Hat
“AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime. Finding and neutralising 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started.”

