![]()
StackHawk Launches Wingman to Autonomously Fix Vulnerabilities During AI Coding Sessions
PR Newswire
DENVER, Sept. 15, 2026
New $10/user/month tool closes the gap between how fast AI writes code and how slowly humans fix it
DENVER, Sept. 15, 2026 /PRNewswire/ — StackHawk, the application security company, today announced the public launch of Wingman, a product that gives software engineers the ability to autonomously fix security vulnerabilities in the same AI coding session in which the code was written. Wingman installs into existing agentic workflows, including Claude Code, Cursor, and GitHub Copilot, so remediation happens as code ships, not as a ticket created by security weeks later.
Individually, overlooked flaws in production software rarely make headlines. Chained together, they form the exact anatomy behind many modern breaches. Wingman’s find-fix-verify loop fixes these flaws as part of the coding process itself, before they can be chained into an exploit.
“The window between vulnerability disclosure and exploitation used to be measured in years. Today, that window can be negative 15 hours, as attackers often exploit vulnerabilities before they’re even publicly disclosed,” said Joni Klippert, CEO of StackHawk. “Meanwhile, engineering teams are shipping faster than ever because of AI coding agents, but security hasn’t kept pace. That mismatch is exactly what’s putting most organizations at risk today.”
Early Successes
Since its initial rollout, Wingman has automatically fixed more than 7,500 vulnerabilities for early-access customers, using more than five different AI coding agents. Ninety-eight percent of those fixes remain resolved, with no regressions.
The fixes include exploit-confirmed, high severity flaws such as remote code execution, SQL injection, and cross-site scripting. These are the categories most commonly implicated in real-world breaches. With Wingman installed, the AI agents found, fixed, and verified the vulnerabilities before they ever reached a security team’s backlog, freeing up the team to perform more high-value work.
“We started this year with a deliberate plan to bring AI into every stage of the software development lifecycle, from requirements through release. Application security is a critical piece in this puzzle, and we wanted a partner who could help us build an agentic security program, not just hand us another scanner,” said George Baker, CISO, CertiPath. “With StackHawk’s Wingman, our engineers can find and fix vulnerabilities in the same agentic session where the code is written, with human review ‘over the loop’ and a verified record of what shipped clean. This is an enabler for scaling security and working down backlogs without slowing the delivery pipeline.”
How Wingman Fixes Vulnerable Code
Wingman is built for individuals and teams developing and shipping code with AI coding agents. The same AI agent that writes an application already understands the application’s architecture, dependencies, and patterns, along with coding standards it inherits from the rest of the team’s workflow. Wingman puts that context to use, scanning the live app, interpreting findings, and fixing vulnerabilities in the conventions the team already follows.
Once installed, Wingman:
- Works inside Claude Code, Cursor, GitHub Copilot, Codex, and Antigravity. No context switch required.
- Auto-triggers when a feature is marked done. Once the agent finishes a feature, Wingman auto-configures and boots the running app, then tests it the way an attacker would. No manual steps.
- Fixes and verifies inside the agent loop. Findings go back to the same agent that wrote the code. It fixes the issue, Wingman rescans to confirm the fix held, and the loop closes automatically.
- Fires before the pull request opens and reports back to the continuous integration (CI) pipeline on whether the commit is clean.
- Provides proof it happened. Every test is tied to a specific commit, giving security teams an attestation record of what shipped secure, without slowing anything down.
- Includes unlimited applications and 50 scans per user, per month.
“Every other security tool finds a code vulnerability and stops at the finding — a recommendation, a ticket, a pull request waiting on an engineer. Wingman fixes it,” added Klippert. “Finding was never the hard part. Fixing and verifying it fast enough to match how engineering teams ship today, at machine speed, inside the workflow, as the code is written, is what security teams have never had the staff or the hours to do. Every unfixed vulnerability sitting in a backlog is a secret door left open. Wingman was built to close it before anyone finds it.”
Availability and Pricing
Wingman is priced at $10 per user, per month. A 14-day free trial is available at www.stackhawk.com/product/wingman. Teams with larger-scale application programming interface (API) discovery and attack-surface visibility needs can pair Wingman with StackHawk Scale, the company’s enterprise offering.
About StackHawk
StackHawk helps software engineering and security teams find and fix exploitable vulnerabilities in the applications and application programming interfaces (APIs) they build, before they reach production. Founded in Denver, Colorado by CEO Joni Klippert and CSO Scott Gerlach, the company builds dynamic application security testing (DAST) and API security tools used by 200+ enterprise organizations worldwide. With Wingman, StackHawk extends that testing engine into the AI coding agent loop, letting teams find, fix, and verify vulnerabilities at the speed code is written. Learn more at stackhawk.com.
Sarah Thorson
Magnitude, Inc.
sarah@magnitude-growth.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/stackhawk-launches-wingman-to-autonomously-fix-vulnerabilities-during-ai-coding-sessions-302878443.html
SOURCE StackHawk
