Automox launches AI-speed mitigation pipeline for unpatchable CVEs
Automox has announced an AI-assisted vulnerability mitigation pipeline designed to address the growing category of security flaws that cannot be remediated through a conventional software patch. The Austin-based endpoint management vendor says its Mitigation Worklet Pipeline uses AI tooling to draft configuration changes and temporary workarounds for unpatchable vulnerabilities within minutes or hours of public disclosure, compared with the days or weeks that manual processes typically require.
The announcement comes on the same day that Microsoft's September 2026 Patch Tuesday shipped 973 CVEs, which Automox described as the largest single Patch Tuesday release on record. The volume illustrates a trend that the company is positioning against: AI-assisted security research is surfacing vulnerabilities faster than remediation workflows can keep pace.
How the pipeline works
When a new vulnerability is disclosed, Automox's automated pipeline evaluates whether it is patchable or requires a configuration-based workaround. For unpatchable flaws, an AI model analyses the advisory and generates a candidate Worklet, which is a scripted automation that can enforce a configuration change or apply a temporary fix across a fleet of managed endpoints. Crucially, Automox says each generated Worklet passes through human review and quality testing before it is published to its Worklet Catalog.
Customers can search the catalog by CVE identifier or by mitigation category, and retain full control over deployment: they choose which Worklets to run, which endpoint groups to target, and when. An activity log and policy results view provide verification that a mitigation has actually executed on each targeted device. A separate "FixNow" mode is available for situations where immediate remediation is required.
Chief executive Justin Talerico said: "AI tooling analyses the disclosure and generates a fix within minutes or hours. Automox then reviews and tests before release. Customers can then confidently run the mitigation across every endpoint in scope, reducing their exposure faster than ever before."
Automox claims its platform is trusted by more than 3,000 organisations and that customers automate up to 96% more patches than with manual processes, citing an IDC study from 2025 that also attributed a 362% three-year ROI to the platform. Neither figure was independently verified in the release.
Market context
The endpoint management and patch orchestration market is well-populated, with Microsoft Intune, Tanium, Ivanti and Qualys VMDR among the platforms addressing overlapping use cases. Automox's positioning is specifically around cloud-native, cross-platform management across Windows, macOS and Linux, targeting mid-market and enterprise IT teams that lack the staffing to operate heavyweight agent-based tools.
The "unpatchable vulnerability" problem is genuine and growing. A significant share of disclosed CVEs require compensating controls rather than a vendor patch, particularly in the period between disclosure and patch availability, or when legacy systems cannot be upgraded. Mitre data consistently shows that configuration hardening and workarounds are among the most common remediation strategies recommended in CVE advisories.
Automox's human-in-the-loop quality gate is a notable design choice. Fully automated, AI-generated script deployment to production endpoints would carry considerable risk; the vendor's decision to retain human review before catalog publication is likely to be a meaningful reassurance for security-conscious buyers operating under frameworks such as ISO 27001, SOC 2 or CIS Controls, all of which require evidence of change-control processes.
The pipeline joins a series of recent Automox product releases, including an MCP server, Jamf and Intune orchestration via its Canopy product, and an integration with Tenable's vulnerability management platform. The Tenable integration in particular suggests a strategy of sitting between discovery and remediation in the security operations workflow, an increasingly competitive position as SIEM and SOAR vendors extend their own orchestration capabilities downward into endpoint control.
Mitigation Worklets are available now to Automox customers with Worklet Catalog access.