VYPR
researchPublished Aug 5, 2026· 1 source

Tenable Hexa AI Automates Vulnerability Remediation with Agentic Routines

Tenable introduces Hexa AI, an agentic engine for its Tenable One platform, designed to automate the entire vulnerability remediation lifecycle from discovery to verification.

Tenable has unveiled Tenable Hexa AI, an agentic engine integrated into its Tenable One Exposure Management Platform. This new capability aims to significantly streamline and automate the often lengthy process of vulnerability remediation, bridging the gap between identifying exposures and applying endpoint patches.

The core problem Hexa AI addresses is the traditional, slow handoff between security and IT operations teams. Typically, identifying a vulnerability and fixing it involves multiple manual steps across different tools, leading to a remediation gap of days or even weeks. This delay leaves systems vulnerable to exploitation. Hexa AI seeks to collapse this timeline by automating the entire workflow: scoping affected assets, deploying the necessary patches or fixes, and verifying that the vulnerability has been successfully remediated.

Hexa AI operates using "intent-driven routines." Users can define their objectives in natural language, such as "patch critical vulnerabilities across MacOS endpoints." The system then uses its understanding of the environment and connected tools, like Jamf for endpoint management, to map the vulnerability to the correct fix and identify the affected devices. Before executing any changes, Hexa AI presents a detailed proposal to the user, outlining the scope, the proposed action, potential blast radius, and confirmation that the action is not reversible.

Safety and control are paramount in Hexa AI's design. The agentic engine operates within the "harness" of the Tenable One platform, ensuring it adheres to user-defined guardrails and permissions. These guardrails can specify operational limits, such as restricting scans on certain asset types or limiting the number of concurrent actions. This human-in-the-loop approach allows organizations to scale autonomy at their own pace, starting with less critical tasks and gradually increasing the scope of automated routines as confidence grows.

Once a proposal is approved, Hexa AI orchestrates the remediation. For instance, it can create a specific group in Jamf containing only the approved devices and then trigger the relevant patching policy. It provides real-time status updates on the remediation progress, device by device, without requiring the user to leave the interface. Post-deployment, Hexa AI automatically schedules a re-scan of the environment to confirm that the vulnerability has been closed.

The system's "routines" are designed to be adaptable. Unlike traditional scripts that can break with infrastructure changes, intent-driven routines can adjust to evolving environments, such as new asset classes or renamed tags. This resilience ensures that automated workflows remain effective over time.

Agent Center, a new dashboard within Tenable One, provides visibility into Hexa AI's activities. It answers key operational questions about what needs attention, what is currently running, what has been handled, and what routines are scheduled, fostering trust and transparency in the AI's autonomous operations.

By automating complex manual routines, Tenable Hexa AI aims to help security teams scale their defenses more effectively, reducing the time from vulnerability discovery to complete remediation from days to minutes and allowing security professionals to focus on more strategic tasks.

Synthesized by Vypr AI