IBM and Red Hat patch 400 bugs in open source software

IBM Australia Limited

By Dylan Bushell-Embling
Thursday, 08 October, 2026

IBM and Red Hat patch 400 bugs in open source software

IBM and Red Hat have revealed that Lightwell, their joint initiative focused on securing open source software, has successfully remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.

The two companies have uncovered, remediated and backported fixes for the vulnerabilities, which were found in widely deployed, production-grade software. The development marks an early success for the $5 billion initiative, which was announced in late May.

The Lightwell initiative combines open source engineering expertise from the two companies with Red Hat’s open source community relationships and secure software supply chain capabilities, and uses AI-assisted engineering workflows to develop version-specific fixes for open source application dependencies in production systems.

Developed remediations are then delivered through secured repositories connected to customers’ existing IT processes, to allow organisations to address difficult or previously unknown vulnerabilities while maintaining their existing software repositories, development pipelines and testing processes.

Red Hat and IBM have meanwhile announced the general availability of Lightwell Clearinghouse, a solution for allowing enterprise users to submit specific open source software dependencies for priority review and remediation. The solution will complement Lightwell Network, which enables IT teams to access verified patches, introduce remediated software into their existing workflows, and establish an ongoing process for addressing vulnerabilities.

Fixes developed through Lightwell are contributed back to upstream open source projects under responsible disclosure protocols, to ensure open source projects can benefit from the project while protections for Clearinghouse participants are maintained.

Red Hat VP and GM Gunnar Hellekson said the initiative has been developed in response to the expanding threat landscape, triggered by the ability of AI agents to exploit old dependencies at machine speed.

“Agents do not care if a codebase is 10 years old or otherwise considered stable, because one small crack is all it takes to chain an attack together. Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime,” he said. “Finding and neutralising 400+ novel vulnerabilities so quickly shows how fast Lightwell can move, and we are just getting started.”

Image credit: iStock.com/Thanakorn Lappattaranan

Related News

DigiCert aims to help tame rogue AI agents

DigiCert has announced support for NVIDIA's Open Agent Safety Platform to help equip...

Cloudflare to become public certificate authority

Cloudflare aims to help website operators and web users navigate the transition to a post-quantum...

ACSC raises critical alert for vulnerabilities in two Citrix products

The ACSC has raised a critical 'act now' alert for vulnerabilities in Citrix NetScaler...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd