Visa Released Open-Source AI Vulnerability Harness
The framework automates security patching for large-scale systems through a multi-phase AI pipeline.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust open-source software to improve overall digital security for the public?
On June 10, 2026, Visa released the Vulnerability Agentic Harness (VVAH), an open-source framework designed to identify and repair security flaws. The system is built on a zero-trust architecture and was updated on August 27, 2026, to include automated remediation and validation capabilities.
Why it matters
This release follows stress-testing via Project Glasswing, which identified over 10,000 critical vulnerabilities in existing industry systems. By providing an automated, open-source tool, the project aims to address systemic security gaps across complex digital infrastructure.
The framework, which holds 2,300 stars on GitHub as of late August 2026, utilizes an AI-driven pipeline to manage the entire lifecycle of a vulnerability. It executes this via discovery, triage, remediation, and validation phases, integrating deterministic controls at every stage.
The players
Visa
A global financial technology company operating a payment infrastructure that supports 160 currencies and connects over 200 countries.
Project Glasswing
A security research initiative focused on stress-testing large-scale systems to uncover critical vulnerabilities.
The details
The Vulnerability Agentic Harness operates using a zero-trust architecture—a security model that assumes no user or device is inherently trustworthy and requires continuous authentication. The pipeline functions by autonomously finding, prioritizing, fixing, and verifying security flaws while maintaining human oversight throughout the process. This approach is intended to replace manual patching workflows with automated, verifiable interventions.
Timeline
April 2026: Visa joined the Project Glasswing initiative.
June 10, 2026: The Vulnerability Agentic Harness was released under an Apache 2.0 license.
mid-July 2026: The GitHub repository reached 595 stars.
August 27, 2026: Visa pushed a major update to the framework.
late August 2026: The GitHub repository reached 2,300 stars.
The Tech Race
This release follows the security stress-testing conducted by Project Glasswing, which sought to measure the resilience of global payment networks. The framework represents a shift toward open-source, automated remediation to combat the scale of flaws identified in the test.
The framework is available under an Apache 2.0 license for developers and enterprises to integrate into their own security stacks. It primarily benefits large organizations managing high-volume payment credentials by automating the identification and patching of security vulnerabilities.
The takeaway
The development signals a broader industry trend toward automating critical security workflows to manage massive, complex datasets. Watch the project's GitHub repository for future updates to the framework's remediation accuracy and new vulnerability detection signatures.
Further reading
For more on evolving threat detection, see Cybersecurity.
Live Poll
Do you trust open-source software to improve overall digital security for the public?









