DKDKCISSPSearch
Vulnerabilities

Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities

This comes as the company announced at the general availability of the Lightwell Clearinghouse following a pilot testing phase.

DKCISSP News DeskInfosecurity Magazine6 Oct 2026, 6:31 pm
Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

The project’s mission is to meet Red Hat’s enterprise customer needs where open-source package versions are at risk today, according to the company.

This comes as the company announced at the general availability of the Lightwell Clearinghouse following a pilot testing phase.

The company, alongside parent IBM, was among the first to respond to the influx of AI-powered vulnerability reporting, creating processes to validate and address genuine flaws while reducing the burden of noisy or inaccurate submissions on open-source maintainers.

Hellekson noted, “Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime.” In July 2026, IBM and Red Hat unveiled two product offerings, Lightwell Network and Lightwell Clearinghouse Premier.

By joining this premium offering, Red Hat customers can submit specific open source vulnerabilities to IBM and Red Hat for priority review, remediation and fixes that can be applied to older software versions still in use.

The initiative was backed by a $5bn investment from IBM and Red Hat, 20,000 in-house engineers dedicated to it as well as “early adopters” from the financial sector, including Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo.

The former has been available from launch and provides immediate access to a continuous stream of digitally signed binaries, source code and comprehensive compliance artifacts, including complete software bills of materials (SBOMs).

Gunnar Hellekson, VP at Red Hat and general manager of Lightwell, said the emergence of AI agents “shifted the threat landscape overnight, exploiting old dependencies at machine speed.” “They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together,” he added.

Both products are built around the Lightwell Clearinghouse, a vulnerability management engine designed to develop version-specific fixes for open-source application dependencies in production systems.

Lightwell Clearinghouse Premier is a more advanced offering designed for select enterprise customers running pinned versions in production who need targeted remediation and backports.

What happened

The project’s mission is to meet Red Hat’s enterprise customer needs where open-source package versions are at risk today, according to the company.

This comes as the company announced at the general availability of the Lightwell Clearinghouse following a pilot testing phase.

What changed

The company, alongside parent IBM, was among the first to respond to the influx of AI-powered vulnerability reporting, creating processes to validate and address genuine flaws while reducing the burden of noisy or inaccurate submissions on open-source maintainers.

Hellekson noted, “Finding those bugs is only half the battle: the real work is backporting fixes directly into active production apps so customers do not have to pick between security and uptime.” In July 2026, IBM and Red Hat unveiled two product offerings, Lightwell Network and Lightwell Clearinghouse Premier.

Who is affected

By joining this premium offering, Red Hat customers can submit specific open source vulnerabilities to IBM and Red Hat for priority review, remediation and fixes that can be applied to older software versions still in use.

The initiative was backed by a $5bn investment from IBM and Red Hat, 20,000 in-house engineers dedicated to it as well as “early adopters” from the financial sector, including Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo.

Why it matters

The former has been available from launch and provides immediate access to a continuous stream of digitally signed binaries, source code and comprehensive compliance artifacts, including complete software bills of materials (SBOMs).

Technical details

Gunnar Hellekson, VP at Red Hat and general manager of Lightwell, said the emergence of AI agents “shifted the threat landscape overnight, exploiting old dependencies at machine speed.” “They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together,” he added.

Both products are built around the Lightwell Clearinghouse, a vulnerability management engine designed to develop version-specific fixes for open-source application dependencies in production systems.

Lightwell Clearinghouse Premier is a more advanced offering designed for select enterprise customers running pinned versions in production who need targeted remediation and backports.

Attribution

Infosecurity Magazine: This comes as the company announced at the general availability of the Lightwell Clearinghouse following a pilot testing phase.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net SecurityHelp Net Security · 6 Oct 2026, 4:14 pmAttackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 8:48 pmOut-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net SecurityHelp Net Security · 5 Oct 2026, 4:08 pmAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pm