Today, AI generates more than 60% of production code, according to New Relic 2026 State of AI Coding Report. That number is only going to rise. And while AI-assisted development has unlocked real gains in velocity, it has introduced a new and largely unaddressed problem: code is shipping faster than teams can verify it, and security is feeling the pressure most acutely.

AI has also accelerated how security vulnerabilities are found and exploited. Open source vulnerabilities have jumped 107%, reaching an average of 581 per codebase, according to the Black Duck Open Source Security and Risk Analysis (OSSRA) report for 2026. Attack surfaces are expanding. The window between disclosure and exploitation, once measured in weeks, has collapsed to hours. And the engineers expected to respond to all of this are already stretched thin with costs of $28,000 per developer per year that IDC attributes to manual security work. 

This is the operational reliability challenge that New Relic Security Rx is built to solve.

New capabilities, one connected remediation workflow.

Security Rx provides engineering teams a runtime vulnerability management solution fully integrated into New Relic Intelligent Observability platform. Its central design principle is simple: security decisions should be grounded in live execution context, not static analysis.

Today we are excited to introduce new capabilities to help teams keep pace with the AI-scale demands: a new modernized security overview page that provides a realtime  CVE advisory, AI recommendations, and helps correlate changes with risk across Apps, Infra, and Cloud, Jira integration, and intelligent remediation with Autopilot Security Rx agent. Each capability builds on the next, taking a team from raw vulnerability data to a verified production fix.

For engineering organizations, the new Security RX capabilities means:

  • Automated remediation workflows: Agent-driven triage, ownership routing, and fix generation directly addresses the cost of manual security work.
  • Enhanced security context: Shifts triage work to the agent layer, so engineers spend their time reviewing proposed fixes with full context rather than hunting for information from scratch.
  • Runtime-verified fixes: Integrations with tools like Jira ensures that a fix is confirmed in production, rather than simply closed in a ticket, changes the risk profile of your remediation program. 

Intelligent remediation with Autopilot Security RX Agent

Security RX Agent closes the loop on the remediation workflow by combining three core capabilities: deep context enrichment using ground truth from live production data, flexible remediation paths that work with GitHub Issues and cloud coding environments, and automated workflow integration that connects directly to Jira.

Deep context enrichment grounds every remediation action in live production reality, not just CVE metadata. The Security Rx agent pulls  loaded library versions, entity relationships from code-to-cloud, and real metrics from your running environment, then packages that execution context and passes it directly to your coding agent. Instead of generating a generic fix based on a CVE description, your coding agent works from a precise, production-grounded picture of the affected service. Engineers receive a targeted fix proposal to review, not a vulnerability report to investigate from scratch.

Flexible remediation paths let teams work within their existing tooling. Whether your developers use GitHub, Claude or other AI coding assistants, Autopilot Security RX Agent feeds each tool the live execution context it needs to generate a precise, targeted fix. Because the coding agent knows exactly which library version is affected, how the vulnerable code is called in production, and which service is at risk, it produces a fix grounded in actual runtime behavior rather than a generic patch based on CVE metadata alone. Engineers spend their time reviewing a well-informed proposal, not starting from scratch.

Intelligent Remediation with Autopilot Security RX Agent brings these elements together through three core functions. Deep context enrichment grounds every action in production truth, pulling live stack traces, loaded library versions, and real call paths so coding agents generate precise, targeted fixes rather than generic patches. Flexible remediation paths meet engineers where they already work, feeding that ground truth context directly to GitHub via Issues  Jira, cloud coding environments, or whichever AI coding assistant your team uses. Automated workflow integration through Jira ties the full loop together, ensuring fixes are routed to the right owners, tracked in real time, and verified in production even when a ticket closes.

Enhanced Security Overview

The Security Overview is your new command center for operational security. It brings together SLAs, remediation burn-down rates, and a security-native version of What's Changed, so your team can track new findings as they surface. At the center is CVE Advisory, which delivers instant details on every newly found and disclosed CVE from the past 30 days. Now instead  of hunting across tools for current exposure, teams get a single view of where things stand, what's changed, and how remediation is progressing from the same live data.

Runtime prioritization

Runtime prioritization sits at the heart of the Security Overview, using New Relic application performance monitoring (APM) telemetry to determine which vulnerabilities are actually running in production. It delivers one shared, prioritized source of truth across major open-source operating systems, packages, and foundational libraries, covering real-time CVE disclosure impact, ongoing health tracking, and clear summaries of what's changed grounded in live production data.

For engineering and security teams, this unified view changes how they work together by providing a prioritized source of truth for vulnerabilities across major open-source operating systems, packages, and foundational libraries. There's no more debating which CVEs matter or hunting down ticket status or siloed reports. When everyone works from the same live picture of production, priority decisions get made faster, progress is measurable, and nothing falls through the cracks.

Jira integration

Runtime prioritization removes friction by giving both teams a live, shared view of what’s actually running in production, so decisions happen faster and effort goes where it matters most. But workflow fragmentation still creates drag: when security and engineering teams operate in different workflows, remediation slows down.

Security Rx integrates directly with Jira to aggregate vulnerability issues, determine ownership based on code and service context, and route tickets to the right teams automatically. As new CVEs are disclosed, the integration reflects their real-time impact, tracks remediation health, and surfaces clear summaries of what's changed across your vulnerability backlog. Two-way sync keeps the New Relic  intelligent platform and Jira aligned in real time, so engineers don't have to manually update two systems, and security teams always have current status. The Jira integration is now generally  available to New Relic customers.

Security for operational reliability: the bigger picture

The framing matters here. Vulnerability management isn't a compliance exercise that runs parallel to engineering work. Unpatched vulnerabilities cause outages, data breaches, and service degradation. They are an operational reliability problem, and they deserve the same tooling sophistication that modern engineering teams apply to incident detection and response.

Security Rx is built on that premise. It is fully integrated into New Relic Intelligent Obserbability Platform, alongside the runtime data your teams already rely on. It uses the same telemetry that powers performance monitoring to power vulnerability prioritization. It connects security posture to production reality.

With AI generating the majority of production code and open source vulnerabilities growing at  growing at an unprecedented rate with a 66.2% surge in CVEs so far this year when compared to the same period in 2025 according to CVE.icu, the organizations that will maintain reliable, secure systems are those that treat vulnerability management as a first-class engineering discipline. That means live context, automated triage, verified fixes, and shared visibility across teams.

Explore New Relic security and reliability solutions  and book a demo to see how live execution context changes the remediation workflow for your team.

Don’t have a New Relic account yet? Sign up now, with no credit card required.

현재 이 페이지는 영어로만 제공됩니다.