Ivanti wants IT teams to know a patch will fail before they deploy it

In July 2026, Microsoft released the largest Patch Tuesday update in the programme's history. Dark Reading reported 622 unique CVEs and Tenable counted 569. In every organisation running Windows, someone had to decide which fixes went first, check which machines received them and explain the gaps to an auditor. Ivanti's research suggests those people are close to their limit. Among the IT professionals it surveyed, 62% said they feel overwhelmed by day-to-day operations and 23% said a colleague had resigned because of burnout.

On 21 July 2026, Ivanti announced Predictive Remediation, a new capability in its Autonomous Endpoint Management (AEM) platform, which runs on Ivanti Neurons. The tool predicts whether patching will meet compliance targets and flags anything likely to stop a patch from installing before the service-level deadline passes.

“Predictive Remediation brings together asset visibility, exposure context, endpoint readiness, predictive compliance and guided action into a practical workflow before patch execution,” said Chris Goettl, Vice President of Product Management at Ivanti, in an interview with The Source Code. “Teams move from knowing what needs to be patched to understanding whether patching will meet the required outcome.”

Vulnerability disclosures are growing faster than IT teams can patch them

Security researcher Jerry Gamblin's annual review of CVE data counted 48,185 vulnerabilities published in 2025. That was 20.6% more than the 39,962 published in 2024, or about 132 a day. According to Dark Reading, Microsoft's Tom Gallagher said in May 2026 that AI would increase patch volumes, and the July release followed. August's update fixed 398 CVEs, the second-largest on record. Ivanti's whitepaper, The Patch Apocalypse, says the average time between a vulnerability's disclosure and its active exploitation is now five days. Ivanti puts this down to attackers using AI to work backwards from published patches.

“As AI accelerates the speed and sophistication of attacks, cybersecurity has never been more important,” Goettl said. “Organisations are facing a growing volume of vulnerabilities, shrinking remediation windows and increasingly complex IT environments.”

Ivanti's report, The Autonomous Endpoint Management Advantage, is based on surveys of more than 600 executives, 3,900 IT and cybersecurity professionals and 8,400 office workers worldwide. Ravn Research conducted them between October 2024 and May 2025. The report found that 39% of IT teams struggle to decide which fixes to prioritise, and 38% have difficulty tracking patch status and rollouts. Office workers reported an average of 6.3 technology interruptions a month. Each of those interruptions stops someone from working and sends a ticket to an IT desk that is already behind.

Patches often stall when work passes from security teams to IT teams

Goettl said the problem often shows up at the point where one team hands work to another. Security teams find and rank vulnerabilities, and IT teams install the fixes, often using different tools. “Managing exposures, for many organisations, still has some data and tool silos,” he said. “Ivanti's Autonomous Endpoint Management platform allows IT and security teams to collaborate more effectively in the last mile of the exposure lifecycle: remediation.”

AEM starts by building an inventory. It keeps looking for every device and application on the network, including ones IT does not manage or know about, and keeps the list current. “The platform continuously discovers and inventories managed, unmanaged and shadow IT assets to create a real-time, authoritative view of devices, software, configurations and security exposures across the environment,” Goettl said. The platform also checks for settings that have drifted away from company policy and corrects them. “The platform monitors for policy violations and configuration drift, automatically initiates corrective actions when needed and maintains a complete record of remediation activity,” he added.

Goettl said the design grew out of the rising number of decisions each administrator has to make. “The volume of decisions required to keep endpoints secure and compliant is rising, driven in part by AI,” he said. “We recognised that effective governance starts with a shared understanding of the environment, so we focused first on establishing a single source of truth across the endpoint estate.”

Ivanti says customers can start patching without new servers

Most IT departments cannot take on a long implementation to fix a problem that grows every month. “One advantage of having a SaaS solution is the ability to rapidly expand the implementation in a very short time,” Goettl said. “Some organisations are able to deploy agents and get immediate value for complex use cases like Patch Management without standing up any additional infrastructure.” He said this works because devices share patch files, so organisations do not need their own distribution servers. The platform uses the MQTT messaging protocol to answer queries and run automated fixes as issues come up. IT staff can also take remote control of a device through a web browser before the Ivanti agent is installed on it.

Some organisations still want a person to sign off on every change. “Many organisations are transitioning from linear approval processes to more dynamic methods of defining risk appetite and configuring the patch solution to remediate based on those definitions,” Goettl said. “However, there are still cases where a stricter approval process is needed.” For those customers, Ivanti Patch Management can plug into existing approval systems, so teams can approve specific CVEs one by one before they are fixed automatically.

Companies will hand patching to software only if they can check its work

Other security firms are also changing how they rank vulnerabilities. After the July release, Qualys' Mayuresh Dani told Dark Reading: “The days of CVSS-only prioritisation are over.” Ivanti's survey shows how far most organisations are from automated patching. Only 32% of IT professionals said their organisations make full use of automation in IT work, and only 52% of organisations use endpoint management tools that show all their devices in one place.

Ivanti chief executive Dennis Kozak said in the July announcement: “AI is only as effective as the data that powers it.” Goettl said customers would need to trust the system before letting it act. “We believe the next era of IT will be defined by autonomy, but autonomy without trust is a risk,” he said. “That's why Ivanti is focused on delivering governed autonomy built on trusted, real-time data and human oversight.”

The July announcement included no results data, so it is not yet clear how well Predictive Remediation works in practice. In Ivanti's survey, 67% of IT professionals said they expect AI and automation to give them time for more interesting work.

Goettl said the goal was to help teams “spend less time on manual work and more time driving innovation for the business.” For the administrators behind those burnout figures, the benefit depends on how much patching their organisations are willing to let the software handle.

Sindhu V Kashyap

Global Technology Journalist & Multimedia Storyteller | Covering Founders, Investors & Leaders Reshaping Tech | Writer · Interviewer · Moderator · Editor

Next
Next

Enterprise AI Has Until January to Prove It Works