Wingman is broadly available today. Here is why we built it, and why the clock is louder than most security programs are acting like it is.
We started StackHawk in 2019 to help engineers fix vulnerabilities. Not find them. Fix them. Finding was already a solved problem. Every scanner on the market could hand you a list. Nobody could get the list fixed.
Seven years later the list is a lot longer. And the people who made it longer are saying so out loud.
Read what they are saying
- February 5, 2026. “Secure as much code as possible while the window exists.” Anthropic Frontier Red Team, on LLM-discovered zero-days
- April 10, 2026. “Patch everything on the CISA Known Exploited Vulnerabilities (KEV) catalog immediately.” And: “Plan for an order-of-magnitude increase in finding volume.” Jason Clinton, CISO, Anthropic, and co-authors
- May 22, 2026. “The bottleneck in fixing bugs like these is the human capacity to triage, report, and design and deploy patches.” Anthropic, Project Glasswing update
- June 8, 2026. Microsoft rated 14 of 21 vulnerabilities “Exploitation Less Likely” or “Exploitation Unlikely.” Anthropic’s model produced working exploits for 13 of them. “N-hour is closer to the reality we now operate in.” Anthropic Frontier Red Team, Measuring LLMs’ impact on N-day exploits
- June 22, 2026. “Defenders are overwhelmed with the number of vulnerabilities found. Instead, the bottleneck is now patching vulnerabilities.” OpenAI, announcing Daybreak
- August 5, 2026. “We said we’re safe because this is rare and it costs a lot. Unfortunately, AI’s changed this. It’s no longer rare.” David Weston, Corporate Vice President, Microsoft, Black Hat USA keynote (via Cybersecurity Dive)
- August 17, 2026. “Work through your existing vulnerability backlog.” “Time is of the essence, and defenders will need to pursue the steps below at turbo speed.” Greg Brockman, President, OpenAI
That is Anthropic, OpenAI, and Microsoft, in their own words, over seven months. I have read all of it, and the message never changes: the stuff you decided you could live with, you can’t anymore. The severity score on that medium was calculated for a human attacker with a day job. The thing probing your app now doesn’t have one. So fix it. Fix all of it.
“Fixing isn’t part of our success criteria”
Here is what makes me crazy. Every week we talk to security teams evaluating vendors, and someone says a version of this: fixing isn’t part of our success criteria.
Excuse me!?
The scorecard is still coverage, findings count, dashboards, integrations. Fix rate is not on it. That scorecard was written for a world where an attacker had to pick which of your bugs was worth their time. That world is gone. A model with unlimited time, unlimited patience, and no shortage of creativity does not triage your backlog. It works the whole thing.
If your success criteria do not include “the vulnerability is gone,” you are measuring the part of the problem that was never hard.
Fix inside the work, not next to it
Here is what we have learned building Wingman: a fix happens reliably only when it rides along with work the business already wants shipped.
A separate queue of security pull requests is a ticketing system with better formatting. It sits. It gets reviewed last. It goes stale against main. No engineer wakes up excited to review PR number 47, “Fix XSS in legacy endpoint.”
Wingman does it differently. It runs inside the coding agent your engineers already use: Claude Code, Cursor, GitHub Copilot, Codex, Antigravity. When the agent finishes a feature, Wingman boots the app, tests it the way an attacker would, and hands the findings back to the same agent that wrote the code. The agent fixes it. Wingman rescans to confirm the fix held. Then the PR opens, features and security fixes together, with an attestation tied to the commit.
The fix gets reviewed because the feature gets reviewed. That is the whole trick.
The Early Data
Cumulative vulnerabilities fixed by Wingman, early-access customers, June through September 13, 2026.
Since June, Wingman has fixed more than 7,500 vulnerabilities for early-access customers across more than five different coding agents, validated fix-held in the agent loop. These are not hygiene findings. The list includes exploit-confirmed remote code execution, SQL injection, and cross-site scripting, the categories that show up in breach reports.
The first two weeks of September fixed more vulnerabilities than all of July. That is what happens when fixing is attached to shipping instead of to a ticket queue. Every one of those fixes landed before a security team ever created a ticket.
Plenty of tools now suggest a fix. Some open a PR. Wingman is the only product that finds, fixes, and verifies inside the agent loop, before the PR exists. Now we have production data that says it works.
Broadly available today
Wingman is available to everyone starting today. Ten dollars per user per month. Unlimited applications and 50 scans per user per month. Fourteen-day free trial. No sales call required.
The experts are not telling you to buy a better dashboard. They are telling you to fix everything, fast. For the first time, that is something you can actually do.
Install Wingman. Finish a feature. Watch it get fixed. stackhawk.com/product/wingman