IBM and Red Hat are expanding access to Lightwell, their open source software security program, by offering it free to more than 185 research universities and 100 nongovernmental organizations (NGOs) and think tanks in the United States.
“Lightwell combines automated remediation with deep open source engineering expertise and contributes fixes back upstream,” said Matt Hicks, President and Chief Executive Officer, Red Hat. “Expanding access will help strengthen both participating institutions and the open source communities on which they depend.”
IBM said eligible institutions will get access to Lightwell’s library of validated fixes for open source software vulnerabilities. Lightwell combines artificial intelligence-driven automation with human engineering expertise to identify, validate and remediate flaws. Participating institutions can use fixes for the software versions they already run, which reduces the need for disruptive upgrades.
IBM and Red Hat’s broader Lightwell push in May 2026, when the companies announced a $5 billion pledge to Project Lightwell. The effort was designed as a centralized clearinghouse for open source security, supported by AI tools and more than 20,000 engineers, with a commercial subscription model targeting enterprises.
[ALSO READ: IBM and Red Hat Commit $5 Billion to Secure Open-Source Software as AI Raises Cybersecurity Risks ]
The new no-cost access program is an extension of the same strategy: build a trusted security layer around open source software, then widen the pool of institutions that can use it. The shift from paid enterprise use to no-cost access for universities and NGOs also suggests IBM and Red Hat want Lightwell to become part of the open source infrastructure conversation, not just the enterprise security market.
IBM says Lightwell helps institutions secure open source software while protecting proprietary data, code and research. That point is important for academic and policy organizations, where the software environment may be public, but the research itself is not.
Lightwell is more centralized and more curated. Traditional open source security often depends on upstream maintainers, community advisories and internal engineering effort. IBM and Red Hat are trying to compress that process into a managed workflow: identify the flaw, validate the fix and deliver a patch that works in the customer’s current environment. Project Lightwell earlier this year as a clearinghouse for open source security, which is the clearest shorthand for what the company is trying to build.
IBM said participating institutions can begin onboarding in August 2026.
To learn more about Lightwell, visit ibm.com/products/lightwell and redhat.com/en/lightwell.




















