Quick Facts

  • Ivanti’s Claude-based AI skill fabricated patch data during training, and the company publicly disclosed the errors and its human review process.
  • Microsoft’s September 2026 Patch Tuesday resolved 973 CVEs, including 119 rated Critical and two actively exploited zero-days, underscoring the stakes of accurate patch prioritization.
  • CVE disclosures now exceed 45,000 annually, triple historical baselines, while average time-to-exploit has collapsed to five days.

Ivanti is the only major security vendor that has publicly described fabrications produced by its own AI and the human review step built to catch them. That disclosure, which no regulation required, raises a direct question for every enterprise security team acting on AI-ranked patch guidance: do you know how that ranking was made?

Chris Goettl, Ivanti’s VP of Product Management for Endpoint Security, spent months training an Anthropic Claude skill on patch data he had processed by hand for a decade. The model kept inventing details. “You see something blatantly wrong, and at some point, you just get fed up, and you say, did you just make that up,” Goettl told VentureBeat. “And it will literally tell you that it has no actual foundation or referenceable material. That was all me.”

The skill draws only on published vendor advisories and Ivanti’s own spreadsheets. It does not touch customer data. Every output is a draft until a human approves it for release.

The efficiency gains are real. A spreadsheet that previously took two people about four hours each now runs in under 30 minutes. The August run was the first production month. Goettl was on vacation. The prioritized Patch Tuesday briefing reaches 500 to 700 webinar attendees each month.

On June 9, Ivanti published a Patch Tuesday post captioned: “Graph generated using Claude (Anthropic) on June 9, 2026, based on author-designed prompts and dataset by Chris Goettl.” The caption has sat on Ivanti’s site for three months. No industry standard required it.

The disclosure stands out because the publications carrying Goettl’s numbers have not reported the AI’s role. Computer Weekly, Krebs on Security, Help Net Security, Cyber Magazine, and Rapid7 all cited his analysis this year. None reported that the guidance is partly skill-produced, what the skill got wrong during training, or the review chain that precedes release.

Kayne McGladrey, a senior IEEE member and independent vCISO, framed the baseline expectation plainly. Writing about the practice in general, not any specific vendor, he said: “The vendor owes their customers one page, in writing, before a single priority task lands in anyone’s queue.”

CrowdStrike and Palo Alto Networks both run human-in-the-loop designs. At Fal.Con 2026, CrowdStrike described a model where an analyst works the same detection in parallel with the agent, comparing verdicts simultaneously. Palo Alto shipped Cortex XSIAM AgentiX in February 2026 with prebuilt agents gated by human approval for high-impact actions. Neither company has publicly disclosed a fabrication catch.

The stakes for accurate guidance are rising fast. Microsoft’s September 2026 Patch Tuesday resolved 973 CVEs, one of the largest single releases on record, including two zero-days confirmed exploited in the wild. July’s 576 CVEs had set the all-time record. August’s 428 took second place. September made both look modest.

Counting those CVEs is not straightforward. Seven trackers published totals for the same Tuesday. Tenable counted 964. Senserva reached 1,169, a 205-CVE gap for the same patch set. Microsoft stopped listing its CVEs directly, making every count a manual parse. AI now sits in the layer between that raw data and the risk tier a security team acts on.

Regulatory pressure is adding urgency. On June 10, CISA issued Binding Operational Directive 26-04, requiring Federal Civilian Executive Branch agencies to patch high-risk vulnerabilities within three calendar days. The directive explicitly cites AI-accelerated exploitation as the rationale. Automox CTO Jason Kikta expects the directive to cascade through federal contractors, cyber insurance requirements, and board-level decisions the same way the Known Exploited Vulnerabilities catalog did.

Ivanti also disclosed that certain ITSM vulnerabilities were discovered through its own use of large language models integrated into product security workflows, a rare instance of AI-assisted vulnerability discovery being credited in a formal advisory.

“What really matters is my subject matter expertise,” Goettl said. “Knowing what’s important, what’s not, having that informed ability to make judgment calls, to give recommendations, to guide the tools to help make this happen.”

Read more: Most vendors won’t tell you when their AI invents your security guidance. Ivanti did.

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.