By Duncan Riley
Publication Date: 2026-10-06 13:00:00
IBM Corp. and its Red Hat unit said today that their Lightwell open-source security program has found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries.
The companies also made Lightwell Clearinghouse generally available. Enterprise customers can use it to submit specific open-source dependencies to IBM and Red Hat for priority review and remediation.
The milestone is pitched at a risk the two companies say is growing as autonomous artificial intelligence agents get better at chaining several lower-risk software weaknesses into one serious attack. Because many businesses still run library versions that are years old, any patch has to be built for the exact release sitting in production.
For the more than 400 flaws, Lightwell engineers backported patches into the widely deployed versions of each library. Any fix that also applies upstream goes back to the open-source project under responsible disclosure protocols while Clearinghouse…

