By MFJ Staff | Sources: Visa, and Stock Titan
Key takeaway: As AI speeds up how fast attackers can exploit a vulnerability, the payments industry’s patching speed has to keep pace or the security gap widens.
Visa has expanded its open-source Vulnerability Agentic Harness (VVAH), an AI-driven tool for finding and fixing software vulnerabilities, adding features the company says can cut some remediation times from weeks to hours.
Visa announced the update on August 27, 2026. VVAH launched in June 2026 and has since been downloaded by what Visa describes as tens of thousands of developers globally. The new version adds closed-loop remediation, which gives the system structured feedback to refine a fix after an initial attempt fails, along with support for multiple AI models — including Anthropic’s and OpenAI’s — configurable without code changes, and optional real-time progress tracking.
“AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster path to action,” said Rajat Taneja, Visa’s president of technology. Visa Consulting & Analytics also launched three related advisory services: an AI Cyber Leadership Education program, a VVAH-informed cybersecurity maturity assessment, and a VVAH cyber risk prioritization roadmap. “Speed to remediation is the new battleground,” said Carl Rutstein, global head of Visa Consulting & Analytics. Brazilian card issuer CAIXA Cartões was named as a client that has used the assessment and roadmap services.
Why it matters: Vulnerabilities in payment infrastructure don’t stay theoretical for long once attackers start using AI to find them faster — a slow patch cycle is what turns a disclosed bug into an actual breach. A free, open-source tool aimed at shrinking that window matters for any merchant, processor, or bank running payment systems that depend on Visa’s network, even though the adoption and fix-time figures come from Visa itself rather than an independent audit.
Source: Visa; Stock Titan












