IBM and Red Hat have unveiled Lightwell, an AI-powered platform built to secure open source software and simplify vulnerability remediation at scale. With open source code making up as much as 90% of enterprise codebases, and AI now accelerating the discovery of hidden exploits, the companies argue traditional patch management can no longer keep pace.
A Response to an Escalating Vulnerability Crisis
An average codebase today contains 581 vulnerabilities, according to IBM and Red Hat. To combat this, the pair launched Lightwell, a platform designed to address the challenge through automated remediation and AI-powered dependency management.
The move builds on a US$5 billion commitment to open source security announced in May 2026, backed by more than 20,000 engineers focused on scaling AI-powered remediation.
Automation Meets Engineering Expertise
Lightwell introduces two offerings targeting enterprise software development teams: Lightwell Network and Lightwell Clearinghouse Premier. Both combine AI-driven automation with human engineering expertise to identify, validate and remediate vulnerabilities in open source dependencies.
The platform uses a generative AI-powered remediation engine that combines frontier AI and open AI models with human expertise to analyse software dependencies, delivering validated fixes for production environments without requiring organisations to upgrade entire software stacks. The technology backports critical fixes directly into long-lived production versions, an approach designed to reduce disruption and minimise regression risks.
"Lightwell represents a fundamental structural shift in how we secure all enterprise software. By pairing automated remediation with our deep engineering heritage, we aim to deliver the trusted infrastructure required to consume open source reliably, sustainably and at AI speeds."— Matt Hicks, President and CEO, Red Hat
Network Offering Targets Development Pipelines
Lightwell Network is now generally available with more than 6,500 remediated, digitally signed and certified application dependencies across ecosystems including Java and Python. Members receive updated binaries, source code, Software Bills of Materials and compliance documentation that integrate directly into existing development pipelines.
The platform follows Red Hat's upstream-first development model, contributing fixes back to the open source community while maintaining enterprise-grade security protections. Development teams can pull certified fixes directly into systems they already run with no retooling required.
"IBM and Red Hat are giving enterprises certified fixes they can pull straight into the systems they already run, with no retooling or disruption, backed by a growing network of technology and delivery partners."— Rob Thomas, Senior Vice President, Software & Chief Commercial Officer, IBM
A Growing Ecosystem of Partners
IBM and Red Hat are positioning Lightwell as an ecosystem backed by an elite roster of technology and consulting partners, including Amazon Web Services, AMD, F5, GitLab, Intel, JFrog, Microsoft, NVIDIA, Palo Alto Networks and ServiceNow, collaborating to integrate security fixes across cloud environments, developer tools and enterprise infrastructure.
Deployment support will come from IBM Consulting, Red Hat Consulting, Accenture, Atos, Cognizant, Deloitte, EY, HCLTech, Infosys, Kyndryl, NTT DATA, Tata Consultancy Services and Tech Mahindra, helping customers map SBOMs, manage software dependencies and integrate Lightwell into existing pipelines.
The challenge could intensify as AI accelerates both software development velocity and the speed at which vulnerabilities emerge — with AI-generated exploits reportedly available for as little as US$50, traditional patch cycles may no longer offer adequate protection.
