Opens in a new tab
vmblog logo 2024 wht (updated)

Lineaje Launches AI System for Continuous Vulnerability Remediation

Share: 

David Marshall | Published: July 21, 2026

Software supply chain security company Lineaje has introduced a platform that it says can continuously identify and remediate exploitable vulnerabilities across proprietary software, open-source components, AI-generated code and containers.

The Continuous Vulnerability Elimination Factory, known as CVEF, combines vulnerability scanning, remediation, testing and verification. It also supports Frontier Defense™, an optional capability designed to address previously unknown vulnerabilities discovered by advanced artificial intelligence models.

The launch comes as companies increasingly use AI coding assistants to speed software development. Those tools can improve productivity, but they can also make it harder for security teams to understand the code and dependencies entering applications.

Lineaje said research from its Lineaje Labs unit found that the percentage of vulnerabilities considered practically exploitable rose from about 1.5 percent to more than 90 percent when attackers used frontier AI models. The company said that shift could turn weaknesses once viewed as low risk into viable attack paths.

“AI is fundamentally transforming both how software is built and how it’s attacked, while regulators are increasingly imposing remediation mandates measured in hours, not weeks,” said Javed Hasan, Co-Founder and CEO of Lineaje. “CVEF with Frontier Defense extends traditional AppSec by enabling enterprises to continuously identify, validate, and remediate all traditional and novel exploitable vulnerabilities within a 24-hour autonomous find-and-fix cycle. Enterprises, even those overwhelmed by vulnerability exposure, can now get to no exploitable vulnerabilities in 90 days and stay there.”

CVEF is designed to connect with existing development and security systems. Its management component coordinates AI agents, remediation workflows, approvals, validation and reassessment.

The Unified Scanner Hub examines source code, repositories, dependencies, build artifacts, binaries and containers. It works with application security scanners and selected frontier models to identify vulnerabilities, supply chain risks, integrity concerns and emerging threats.

When an exploitable vulnerability is found, AI agents can create a remediation plan, generate a proposed fix and coordinate testing. Approved changes can then be carried out under company policies and human oversight.

Lineaje said the platform can deliver pre-tested fixes through developers’ existing coding environments and security pipelines. The company claims the approach can reduce developer effort required to address traditional and newly discovered vulnerabilities by as much as 90 percent.

Frontier Defense is aimed at vulnerabilities found by frontier models and large language model-based security platforms. According to Lineaje, the system can generate compatible patches and verify that those changes resolve the identified weakness.

The capability coordinates nine secured sandbox environments used to investigate potential vulnerabilities, create working exploits and generate remediation patches. A centralized system records vulnerabilities, verified exploits and proposed fixes across multiple model runs.

“Organizations are rapidly adopting AI to increase developer productivity and velocity, and we believe software supply chain security needs to be a top priority for risk management programs,” said Melinda Marks, Practice Director, Cybersecurity at Omdia. “Lineaje’s work in this area is valuable as organizations need modern application security capabilities that don’t just alert, but actively assess, remediate, verify, and govern software risk within development workflows. Lineaje’s outcome-based approach directly addresses this operational bottleneck.”

The company is positioning CVEF as an alternative to products that primarily generate alerts and leave investigation and remediation to engineering and security teams. The platform also records approvals, testing results and remediation actions.

“Enterprises are under pressure to reduce software risk without adding more complexity to already stretched security and development teams,” said Srijit Menon, Partner, Digital Trust and National Head, Third Party Risk Management, KPMG in India. “Through our alliance with Lineaje, we are helping organizations take a more proactive and resilient approach to software supply chain security. Innovations complement this effort by helping improve software transparency and vulnerability management. Together, we can bring greater automation, visibility, and governance to complex software ecosystems while reducing risk and strengthening cyber resilience.”