Vicarius Launched ScriptAI for Automated Vulnerability Fixes

The platform automates the creation and deployment of custom remediation scripts for vulnerabilities lacking official patches.

Updated on Sept. 23, 2026 in Cybersecurity

Isometric editorial illustration of a modular metallic server rack unit with a geometric core, representing automated software vulnerability remediation.
Vicarius launched ScriptAI, a new engine integrated into its vRx platform that automates the creation and deployment of security patches for software vulnerabilities. AI Illustration. Upload story photo >

Live Poll

Do you trust automated AI tools to fix security vulnerabilities in your personal software?

Vicarius has released ScriptAI, a new engine integrated into its vRx platform that drafts, verifies, and executes Bash and PowerShell scripts to mitigate software flaws. The service is now available to existing vRx customers, targeting the gap between vulnerability disclosure and vendor-supplied patches.

Why it matters

Security teams often face a significant window of exposure before official patches arrive, and this tool aims to shrink that gap by automating the development of custom fixes. It addresses the growing pressure to mitigate exploits faster, a challenge highlighted by the 53-day average mitigation timeline seen in 2024.

The engine generates custom Bash and PowerShell scripts that perform pre-checks, apply fixes, and verify outcomes against a deterministic judge. The process completes in under an hour, compared to the 53-day average mitigation window recorded in 2024.

The players

Vicarius

A cybersecurity firm founded in 2016 that provides vulnerability remediation tools and manages the vRx platform.

The details

ScriptAI operates by drafting detection and remediation logic which is then subjected to a verification process by human researchers. Before executing any code at the operating system level, the platform uses a deterministic judge—a system that produces the same output for a given input—to validate the fix. If the script fails during the pre-check or verification phase, the system automatically rolls back the changes to maintain system stability.

Timeline

  1. 2016: Vicarius commenced operations.

  2. August 2023: Vicarius released the vuln_GPT model.

  3. January 2024: The company raised $30 million in Series B funding.

  4. September 23, 2026: Vicarius launched ScriptAI.

The Tech Race

This release follows the company's 2023 debut of its vuln_GPT model, marking a shift from pure vulnerability identification to automated active remediation. It positions Vicarius as a competitor in the space of autonomous security operations by reducing reliance on manual patch management.

Existing vRx platform customers can now utilize the engine to deploy custom scripts without waiting for third-party vendor updates. The tool works across various operating systems using native Bash and PowerShell, though it requires existing administrative access to the relevant infrastructure.

The takeaway

Vicarius is betting that automating the creation of bespoke fixes will effectively bridge the dangerous lag time between a vulnerability being public and a patch being issued. Security teams should monitor whether this automated approach succeeds in reducing the average 53-day mitigation window observed in 2024.

Further reading

For broader trends in enterprise defense, explore our Cybersecurity section.

Live Poll

Do you trust automated AI tools to fix security vulnerabilities in your personal software?