Vulnerability management in the age of AI
- Last updated 10/01/2026
-
AI is changing the way everyone works: hacker, red team member, or IT administrator alike.
You've been preparing for this moment for a long time. You put systems in place. You managed devices, patched them, and kept operating systems up to date. You used virtual desktops, so not a trace of data was left behind. That work matters more than ever.
More vulnerabilities to fix: the impact of AI on vulnerability discovery
Frontier AI models accelerate vulnerability discovery. Through Project Glasswing, Anthropic reports that Claude Mythos has identified thousands of high and critical-severity vulnerabilities across a range of software, including flaws in operating systems and web browsers. OpenAI reports that its Daybreak program has uncovered high-severity vulnerabilities in a web browser engine, a mobile operating system, and a popular database, along with more than 400 vulnerabilities that can lead to privilege escalation in an operating system kernel.
What is happening? According to OpenAI, the bottleneck is not finding vulnerabilities; it's patching them. You likely feel that pressure in today’s patching cycles.
Source: Source: CrowdStrike Patch Tuesday Analysis, Oct 2025-Sept 2026
Vulnerabilities are now the top way in
Published Common Vulnerabilities and Exposures (CVEs) continue to grow, while time to remediate is lagging, and this further increases risk. Exploited vulnerabilities are now the most common initial access vector, involved in 31% of breaches and up 55% in a single year. Meanwhile, the mean time to remediate (MTTR) stretched to 43 days, up from 32 days (Verizon 2026 Data Breach Investigations Report).
The time to exploit continues to shrink
Hackers, often leveraging AI, are exploiting vulnerabilities faster than ever. In 2018, the average gap between a published vulnerability and a working exploit was 2.3 years. As of early 2026, exploits precede public disclosure of common vulnerabilities and exposures (CVEs) by more than one day, according to Zero Day Clock.
Close the gap between finding and fixing
To stay ahead, you need to move from findings to fixes faster. That's why we built Omnissa Workspace ONE Vulnerability Defense, now generally available for Windows devices. It brings vulnerability findings and endpoint action together in the Workspace ONE UEM console, so you can assess, prioritize, remediate, and track it all in one place. Pull in findings from CrowdStrike Falcon Exposure Management and see exploitation likelihood, severity, and affected device counts in your UEM console. Then fix what matters from that same console: patch OS vulnerabilities with granular patch management, and update apps with prepackaged versions from the Workspace ONE Enterprise App Repository, home to more than 10,000 apps.

AI-powered agents can quicken the pace
Need to go faster, with controls in place? The new Vulnerability Defense agent runs assessment, prioritization, remediation, and tracking continuously. The agent sets up the fix, and you review and approve it before it deploys.
And don’t forget about mobile vulnerabilities
Did you know that Omnissa extends vulnerability insights to mobile, too? Workspace ONE Mobile Threat Defense tracks OS and app vulnerabilities on mobile devices and so that you can evaluate device compliance.
Identity-based attacks continue to accelerate
The acceleration of attacks via AI is also felt in the identity and access management space. What’s happening there? The emergence of near-autonomous AI-accelerated campaigns is one thing to note, along with the general use of AI by threat actors.
We continue to actively expand our capabilities in this area. We can help secure unmanaged devices with solutions ranging from VDI to secure browsing with endpoint integrity checks. This year we have strengthened Omnissa Acess with Device Bound Session Credentials. We’ve also eased both IT and end user experiences with macOS platform SSO as well as identity integration with Apple Business Manager.
Stolen credentials remain a leading risk
We know that credentials can be leveraged in attacks, with 39% of breaches relying on stolen credentials (Verizon DBIR 2026). So what’s next? The FIDO2 passkeys are easy to use and resistant to phishing but have a key limitation: consumer passkeys can sync across devices. In a corporate environment, you need control over where keys live and which devices can use them.
Enterprise passkeys in Omnissa Access close the gap by binding passkeys to devices
Our new Omnissa Pass Advanced capability (Beta Oct 2026) binds FIDO2 standard passkeys to corporate devices through policy, easing authentication and reducing access risk. Users onboard via the Pass app on iOS and Android, or on the web. Conditional access applies to every phishing resistant login; device compliance is synced from Workspace ONE UEM and processed via Omnissa Access. Proximity checks and cross-device link verification to shuts down remote relay attacks and adversary-in-the-middle exploits. The result: strong authentication that's easy to administer and easy to use.
More context, applied continuously
Authentication is only the start. The Security Events Service turns access decisions from a one-time login check into continuous evaluation. Built on OpenID Continuous Access Evaluation Profile (CAEP), an open standard for signal exchange, it shares real-time security signals from Workspace ONE UEM, Omnissa Intelligence, Omnissa Access, and third-party tools with enforcement points including Omnissa Horizon, Access, and Workspace ONE Tunnel. It's designed to help close the exposure window from hours to seconds.
Workspace ONE Tunnel can provide more vital information as well. New behavioral indicators (currently offered in limited availability) let you enforce access only during shift hours for frontline workers, which helps you align with worker councils and local labor laws; and allow for geographic restrictions that limit access according to country-scoped device location.
Phishing has moved beyond email
Most phishing attacks now happen outside email, through QR codes, text messages, and messaging apps. Workspace ONE Mobile Threat Defense, recently recognized as a leader in mobile threat management by QKS Group, now includes new mobile security tools built into Workspace ONE Intelligent Hub, so employees can check before they click. The QR Code & URL Scanner returns a safe or phishing verdict in seconds, with no VPN or DNS monitoring required. The Suspicious Message Verifier checks SMS, iMessage, and messaging app content before employees respond. Users can share a link, QR code photo, or message to Hub straight from their phone's share menu, and admins get privacy-protected visibility into phishing detections across the fleet. As always, risk information can carry over to UEM for mitigation and response.
Closing gaps in your environment
Every handoff between tools and teams is a place where risk can hide, and consolidated workflows and teams catch more attacks. Vulnerability Defense brings security and IT teams together in a single workflow. Omnissa Secure Access Suite does the same for access, helping you secure contractors and bring-your-own-device (BYOD) users. It combines a unified app catalog, push and token multi-factor authentication (MFA), zero trust network access (ZTNA) for native and web apps, and enterprise web security from Google, so workers get one experience for native, web, and virtual apps on any platform.
And a new Tunnel extension for browsers applies your existing device traffic rules in the browser, with no device management required.
Securing AI itself
We start with AI, and we end with AI. How do we protect your organization from shadow AI, among other things? Read more about that here. AI agents are joining your workforce, and they need the same protections as your people and devices.
We will extend security and compliance to AI agents. It is vital to know what services agents are communicating with and to implement controls to constrain those AI-related services. This includes the discovery of AI agents and large language models (LLMs) through digital employee experience (DEX); secure configurations and provisioning with AI policies via Workspace ONE; and containerized environments for AI via Horizon.
Things to uphold as we move forward
The innovation continues, with AI agents for specific IT and security work (related announcements here). In tandem with that, we will continue to work with you to uphold best practices for EUC IT and security:
- Proactive hardening: Deploy secure, immutable configurations with unified endpoint management (UEM).
- Establish identity: Fingerprint users, software, devices, and agents.
- Minimize risk: Apply least-privilege policies to minimize noise.
- Remediate faster: Prioritize and patch CVEs with automation.
- Recover fastest: Reprovision devices over the air without delay.
Ready to strengthen your organization's security posture? Contact us to start exploring your options.