Google CodeMender: AI-Powered Code Vulnerability Remediation
News | 22.07.2026
AI-driven vulnerability management moves from manual bottleneck to autonomous, high-speed remediation.
As adversarial AI accelerates attacks on software supply chains, security teams need machine-speed defenses that can automate code remediation and counter AI with AI. Google has now released CodeMender in preview, a managed code security agent that scans, verifies, and patches vulnerabilities across enterprise codebases.
What was announced
Google announced the preview availability of CodeMender, a managed AI agent for code security. It is delivered through the Gemini Enterprise Agent Platform and can also be deployed as a core component of AI Threat Defense. CodeMender aligns with Google's multi-model approach, letting organizations select the model that best balances cost, speed, and deep scanning performance. Support for third-party frontier models is planned later this year, while CodeMender with Gemini 3.5 Flash Cyber remains exclusively available to a limited set of governments and trusted partners.
CodeMender consistently identified critical vulnerabilities that our other AI-enabled tools completely missed. It does not just find theoretical flaws, it proves the immediate risk and delivers targeted, validated fixes
Why this matters
For CIOs, CISOs, and IT directors, the traditional vulnerability lifecycle, scan, triage, patch, is often broken by alert fatigue, false positives, and slow manual verification. CodeMender addresses these pain points by proving exploitability before remediation, so security and development teams can prioritize validated risks rather than theoretical findings. It reduces zero-day exposure, keeps development velocity intact, and integrates directly into existing CI/CD pipelines and developer tools such as VS Code and Antigravity.
Technical details
- Multi-model flexibility: choose from multiple Gemini models to optimize for cost, speed, and deep scanning.
- Language coverage: supports C/C++, Go, Java, Python, Ruby, Rust, and TypeScript.
- Vulnerability classes: memory corruption, injection, web security flaws, cryptographic issues, and insecure data handling.
- Exploit verification: builds and runs proof-of-concept exploits in a customer-managed sandbox.
- Automated remediation: generates code diffs with LLM-as-a-judge validation to preserve application functionality.
- Enterprise governance: VPC traffic routing, data isolation, encryption, and zero retention of source code data.
- Integrations: CI/CD workflows, CLI client, Wiz Security Graph, and Wiz Red Agent for AI pentesting within AI Threat Defense.
Softprom and Google
Softprom is the official partner of Google. Our team helps enterprises evaluate, deploy, and scale Google Cloud security solutions, including the Gemini Enterprise Agent Platform and AI Threat Defense with CodeMender.
Learn how to modernize your application security with Google and request a consultation from Softprom experts.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.