ComputeLabs Research

Mandiant’s Agentic Vulnerability Discovery Harness found more than 100 true-positive critical vulnerabilities in two days and contributed to 12 CVEs.

· ComputeLabs Research · from the August 18, 2026 edition

Mandiant said its Agentic Vulnerability Discovery Harness, or AVDH, found more than 100 true-positive critical vulnerabilities in two days during a recent incident-response investigation involving stolen corporate repositories. The company said the work took a fraction of the time required for a manual review.

Mandiant has used AVDH for 10 months across environments containing tens of millions of lines of code. It has executed thousands of pipelines and produced tens of thousands of findings, with the framework used in proactive reviews, penetration tests, red-team operations, and incident response.

The work uncovered dozens of assignable flaws in widely used web extensions and open-source projects and resulted in 12 assigned Common Vulnerabilities and Exposures, or CVEs. The source specifically identifies CVE-2026-13242 and CVE-2026-55803 and says another dozen flaws were in active disclosure.

AVDH combines multiple AI agents with a structured orchestration layer and human subject-matter expertise intended to validate findings skeptically. Mandiant also reported finding a remote-code-execution vulnerability in a client web application, and said AVDH can operate alongside CodeMender’s continuing scans as a two-layer defense.

All 20 stories from August 18, 2026