CFOtech US - Technology news for CFOs & financial decision-makers
United States
IBM, Red Hat offer Lightwell free to US institutions

IBM, Red Hat offer Lightwell free to US institutions

Thu, 6th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

IBM and Red Hat are offering Lightwell at no charge to selected universities, NGOs and think tanks in the United States. The programme covers more than 185 research universities and 100 non-governmental organisations and policy institutes.

The move expands access to a system the two companies introduced earlier this year to address vulnerabilities in open source software. Under the arrangement, eligible institutions can use a library of validated fixes for the software versions they already run.

Open source software sits at the heart of university research systems, teaching platforms and campus operations, as well as the digital infrastructure NGOs and think tanks use for policy work and public-interest programmes. Those organisations often have limited engineering resources to respond quickly when software flaws are found.

Lightwell is designed to identify, validate and remediate vulnerabilities in open source dependencies by combining automated tools with engineering work. Participating institutions can integrate remediated packages into existing software pipelines instead of overhauling systems through broad software upgrades.

The service does not require access to an institution's proprietary source code, data or research. Instead, it is designed to work within existing environments while supplying digitally signed fixes, source code and compliance documents, including software bills of materials.

Broader Push

The expansion is another step in IBM and Red Hat's broader effort to build a commercial and institutional network around open source security. When the companies launched Lightwell in May, they linked it to a USD $5 billion commitment and said more than 20,000 engineers would support efforts to secure the open source software supply chain.

In July, they added Lightwell Clearinghouse Premier, extending the model to open source packages used in active production environments. Since launch, the number of validated and remediated package versions available through Lightwell has risen from 6,500 to more than 8,000, according to the companies.

That total includes fixes for 64 previously undisclosed vulnerabilities, the companies said. The focus on older or long-lived software versions may appeal to universities and non-profit organisations that cannot easily replace or upgrade systems tied to research projects, teaching tools or operational processes.

Lightwell is also positioned as a way to reduce the time needed to respond to vulnerabilities as artificial intelligence speeds software analysis and, potentially, the discovery of exploitable flaws. For institutions with stretched security teams, applying a validated fix to a current version may be more practical than reworking applications around a newer release.

Existing Network

The university and non-profit programme builds on Lightwell's earlier work with large financial institutions. IBM and Red Hat have named Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo among organisations already involved.

A broader group of technology companies is also collaborating on the initiative, including Amazon Web Services, AMD, F5, GitLab, Intel, JFrog, Microsoft, NVIDIA, Palo Alto Networks and ServiceNow. The goal is to move fixes more consistently across development tools, cloud systems, deployment pipelines and network controls.

For universities, NGOs and think tanks, the offer will likely be judged on whether it reduces manual remediation work without adding operational complexity. Many of these organisations rely heavily on open source software but do not have the same budgets or staffing levels as banks or major technology companies.

Matt Hicks, President and Chief Executive Officer of Red Hat, outlined the rationale for the expanded access.

"Lightwell combines automated remediation with deep open source engineering expertise and contributes fixes back upstream," Hicks said.

"Expanding access will help strengthen both participating institutions and the open source communities on which they depend," he said.