Log inGet Assessment

Agentic Remediation: Because You Can't Prioritize Your Way Out of 59,000 VulnerabilitiesWhy autonomous and semi-autonomous remediation, with full transparency and control, is the only way to keep pace.

With 130+ new CVEs a day, ranking vulnerabilities no longer reduces risk. Patrick Münch on agentic remediation: AI agents that plan, execute and verify fixes, with the right level of human control for every change.

Patrick Münch
Patrick Münch
·9 min read·
Agentic Remediation: Because You Can't Prioritize Your Way Out of 59,000 Vulnerabilities

Vulnerability management is changing faster right now than it has in the last twenty years. The shift is already underway, and it's to agentic remediation: AI agents that plan, execute and verify fixes. They work autonomously where it's safe, and semi-autonomously, with a human approving, where the stakes are higher. Here's why prioritization alone can't get us there, and what it takes to make agentic remediation something you can trust.

Let's start with the math.

In 2025, 48,185 CVEs were published. That's a 20% jump on the year before and roughly 132 new vulnerabilities every single day. FIRST forecasts around 59,000 this year, and says 70,000 to 100,000 would not be a surprise. About 40% of last year's CVEs were rated critical or high. That's close to 20,000 "urgent" findings in a year, or about 55 a day.

Now ask yourself how many fixes your team can safely test, schedule and deploy in a day.

For most organizations I talk to, the honest answer is a small fraction of that. And that's the problem nobody in our industry likes to say out loud: prioritization was designed for a world where the backlog was manageable. That world is gone.

Prioritization doesn't fix anything

For the last decade, the answer to too many vulnerabilities has been better ranking. CVSS, then EPSS, then risk-based scoring, then context and attack paths. All of it useful. None of it closes a single vulnerability.

Prioritization tells you what to do first. It doesn't do it. You still end up with a sorted list, a ticket queue and a team that can only work through the top of it. When everything above the cut line is still "critical," you haven't solved the problem. You've just organized it. When everything is P1, nothing is P1.

And the clock has changed. VulnCheck's data for the first half of 2026 shows nearly one in four known exploited vulnerabilities was exploited on or before the day it was disclosed. The median time from publication to confirmed exploitation dropped from 120 days in 2025 to 80. Your prioritization meeting, your change advisory board and your monthly patch window were all built for a slower world.

Then there's AI. Attackers and researchers are using it to find flaws faster, and defenders are pointing it at their own estates too. That means more findings, not fewer. If your strategy depends on humans reading, ranking and hand-fixing every one of them, AI makes your problem worse, not better.

For too long, our industry has admired the problem instead of focusing on the solution. More scanners, more dashboards, more ways to score and sort. The bottleneck isn't finding or ranking. It's fixing.

Automate the fix, not just the ticket

The only way to keep up with machine-speed discovery is machine-speed remediation. That means agentic AI that doesn't just open a ticket, but works out the right fix, understands what it will touch, executes it and verifies the exposure is actually gone.

Fully autonomous AI remediation can sound like nirvana. But security professionals understandably don't want to give up control of, or visibility into, the security actions being taken across their organization. And they're right not to. "Let an AI agent change my infrastructure" is a sentence that makes good engineers nervous, and it should. One bad change on the wrong system costs you more than the vulnerability ever would.

So the question isn't whether to automate remediation. It's how much autonomy to give it, and where.

Confidence and control: two questions decide the level of autonomy

We think about it as two questions for every fix:

  1. How well do we understand the fix and its impact? Is this a known, repeatable change (a patch with a clean track record, a hardening setting, removing unused software) or something novel? Do we know whether it needs a restart, a service shutdown or a dependency change?
  2. How operationally critical is the target? A laptop in the sales team is not a production database serving your customers.

The answers put each remediation into one of three modes: autonomous, semi-autonomous or human led.

Autonomous. The fix is well understood and the target is operationally lower risk: workstations, developer machines, non-production environments. Here the agent should just do it. It applies the fix, verifies it worked and reports what happened. No ticket, no queue, no waiting for the next patch window. This is where most of the volume lives, and where most teams are burning the most time today.

Semi-autonomous. The target is critical: production services, customer-facing systems, databases. The agent still does the heavy lifting. It identifies the fix, works out the operational impact (Does this need a restart? Will it take the service down? What depends on it?), proposes when to run it and prepares the change. A human stays in the loop and makes the call. Once approved, the agent executes and verifies. Your experts spend their time on decisions, not on research and keyboard work.

Human led. The fix is new, unusual or the impact isn't well understood yet. People design and review it. Every time it runs safely, it builds the track record that can move it into one of the automated modes later.

The line between those modes is yours to set, and you can move it as trust grows.

Transparency is what earns the right to automate

No security leader should hand control to a black box. Agentic remediation only works if you can see exactly what the agents are doing and why. For us, that comes down to four things.

Dedicated agents with a clear job. Not one general-purpose AI with the keys to everything. Each agent has a defined role and scope, such as patching endpoints or hardening a configuration, and only acts within it. You always know which agent did what, where and when.

A remediation plan before anything changes. Every fix starts as a plan you can read: what the exposure is, what will change, on which systems, in what order and how it will be verified. If you wouldn't accept a change request without those details from a person, you shouldn't accept it from an agent.

An impact statement for every action. Will it need a reboot? Does the service need to stop? What depends on this system? What's the rollback? The impact statement is what lets a human approve a production change in minutes instead of days, and what lets you trust the agent to act alone on a workstation.

Risk decisions based on your environment, not ours. A CVSS score can't tell a test VM from the system that runs your payroll. At Mondoo we go beyond CVSS with risk dimensions that put each exposure in context and validate it: how exposed the asset is (attack surface), what a compromise would reach (blast radius), how important it is to the business (business priority), whether it's being exploited in the wild (exploitability, using EPSS and CISA KEV) and whether it's trending in the news. A medium-severity CVE that's actively exploited on an internet-facing system matters more than a critical one with no known exploit on an isolated box. You can tune those weights and annotate your own assets, so the model reflects your IT infrastructure, your risk appetite and your scoring, not a generic one. That context isn't there to build a longer ranked list. It decides how each fix gets handled: which run autonomously, which go semi-autonomous for approval and which stay with your team.

Every action the agent takes, and every action it decides not to take, is logged and explained, and that record can be evidenced automatically, on demand, whenever an auditor asks. No more weeks of screenshots and spreadsheets before an audit. That's what turns automation into something a CISO can sign off on and an auditor can follow. Over time, it builds operational confidence and resilience in your security operations: your team knows what changed, why, and what happens next, and every verified fix makes the next decision to automate an easier one.

Add capability, not complexity

There's a trap here, and plenty of vendors will walk you into it. Agentic remediation can't mean ripping out the tools you run today and replacing them with a new platform and a new agent on every machine. That's too costly, too disruptive, and it throws away years of investment in process and people.

Your organization already has the machinery to change systems safely. Endpoint and device management, EDR, DevOps pipelines, infrastructure as code, ITSM and change management, asset inventories. Your teams know these tools, trust them and have built their processes around them.

Agentic remediation should sit on top of that. The agents work out what to fix and how, then execute through the DevOps, IT and asset management capabilities you already have, following the change processes you already run. Nothing to rip out, no parallel tooling to maintain, no new process for your IT team to learn.

You're adding capability, not complexity. And you get value from the first fix, not after a year-long migration.

Fixed should mean fixed

There's one more piece that matters as much as speed: making the fix stick.

Too many vulnerabilities we "fix" come back. A configuration drifts, a new image ships with the old setting, someone re-enables a service for a quick test. If remediation is a one-off action, you'll be fixing the same thing again next quarter.

When a fix is expressed as policy and continuously enforced, it stays fixed. That's what we mean at Mondoo by Fix Now. Fix Forever.

Measure what matters

If you take one thing from this post, change what you measure. The number of vulnerabilities you found, and how well you ranked them, says very little about your risk. What matters is how long exploitable exposures stay open, and how much of that window you're closing automatically.

That's the metric attackers care about, so it's the one we should care about too.

The result: fix at pace and scale

Put it all together and you get what security teams have been missing for a long time:

  • Confidence that fixes are right, because every action comes with a plan and an impact statement.
  • Assurance that you can prove it, with evidence available on demand for every audit.
  • Control over where autonomy starts and stops, set by your risk appetite and your environment.
  • Resilience, because exposures close in hours instead of weeks, and fixes stay fixed.

That's the real outcome of agentic remediation. Not more findings or a better-ranked backlog, but the ability to fix at pace and scale.

What we're building at Mondoo

At Mondoo, our customers come to us because they want to fix things, not just find them. That's exactly what we're building here: agentic remediation that works with the tools you already run, with transparent plans and impact statements for every fix, and with you in control of how much autonomy to hand over.

If you're stuck sorting an ever-growing backlog, I'd like to hear from you. Let's talk about what it would take to stop prioritizing and start fixing.

About the Author

Patrick Münch

Patrick Münch

Co-Founder & CSO

Chief Security Officer (CSO) at Mondoo, Patrick is highly skilled at protecting and hacking every system he gets his hands on. He built a successful penetration testing and incident response team at SVA GmbH, their goal to increase the security level of companies and limit the impact of ransomware attacks. Now, as part of the Mondoo team, Patrick can help protect far more organizations from cybersecurity threats.

Ready to Get Started?

See how Mondoo can help secure your infrastructure.