Cogent Security raises $42 million as AI agents tackle vulnerability remediation bottleneck

2 Sources

Share

Cogent Security secured $42 million in Series A funding led by Bain Capital to scale its AI agents that automate vulnerability remediation. The platform reduces high-risk bug resolution time by 97% on average, addressing a critical bottleneck as software vulnerabilities jumped 162% in five years. Dozens of Fortune 1000 companies already deploy the system.

Cogent Security Secures $42 Million Funding to Scale AI Agents

Cogent Security closed a $42 million Series A funding round led by Bain Capital, with participation from Greylock Partners, Definition Capital, and founders from OpenAI, Abnormal Security, and Datadog

1

. The investment brings the startup's total funding to $53 million since its founding in 2025

2

. Bain partner and former Symantec CEO Enrique Salem, who led the round, described a multi-year courtship of founder and CEO Vineet Edupuganti that began before the company's formal launch

1

.

Source: Fortune

Source: Fortune

Addressing the Vulnerability Remediation Crisis

The cybersecurity landscape faces a mounting crisis. In 2025, more than 48,000 new common vulnerabilities and exposures in software were reported—a 162% jump from five years prior

1

. Attackers increasingly use AI to probe fresh bugs within minutes of disclosure, creating an asymmetric race that security teams are losing. "There are more vulnerabilities than you'll ever be able to remediate or imagine," Salem told Fortune. "The Holy Grail is, how do you figure out what to remediate because you'll never remediate everything"

1

. The problem isn't finding vulnerabilities—it's coordinating their resolution across sprawling enterprise environments.

How Cogent Security's AI Agents Automate the Entire Process

Cogent Security develops autonomous AI agents designed to close the operational gap between vulnerability discovery and remediation in enterprise environments

2

. The platform doesn't replace existing security tools but sits on top of them, integrating with existing security tools companies already use—scanners, internal asset lists like ServiceNow, and data from cloud and endpoint security systems

1

. "We aggregate insights from all those signals, make sense of it, determine what to do, and then push action through the hands and the feet," Edupuganti explained, referring to integrations with ticketing and patching systems

1

.

Source: SiliconANGLE

Source: SiliconANGLE

Enterprise Vulnerability Remediation at Scale

The AI agents operate across security and engineering systems to handle post-detection workflows while maintaining governance controls and auditability

2

. Security teams arrive each day to "thousands or millions of vulnerabilities" requiring judgment and execution, according to Greylock partner Saam Motamedi, who led Cogent's $11 million seed round

1

. The system analyzes contextual data to determine asset ownership, map vulnerabilities to affected services, and assess real-world risk based on environmental factors

2

. It then uses models from Anthropic and OpenAI to help write the code that actually remediates issues

1

.

Measurable Impact on Cybersecurity Operations

Cogent says its customers are reducing the time high-risk bugs stay active by about 97% on average

1

. "Security teams are drowning in coordination work—chasing down system owners, writing tickets, proving fixes happened," Edupuganti said. "We built AI agents that handle that work end-to-end, so security teams can finally keep pace with attackers"

2

. Salem noted that Cogent's platform enables teams to accomplish five times more with the same resources, representing "a fundamental reset of what's possible in security operations"

2

.

Governance and Controlled Autonomy for Enterprise Deployment

Cogent's design targets big, regulated companies that need tight controls. Every AI action can be tracked and replayed, running only within clear, customizable approval rules set by customers

1

. "You have to really make it clear for every decision that an agent is making, why is it making that decision, what's the impact," Edupuganti explained, adding that the product surfaces explanations and confidence levels so customers can "inspect it and then choose when they want to make the full plunge" into autonomy

1

. Many customers start cautiously, letting Cogent automate investigation, prioritization, and routing while humans retain the final software vulnerability remediation step. Over time, some grant full autonomy in safer development environments, gradually expanding "slices of autonomy"

1

.

Market Traction and What's Next

Despite launching formally only in July 2025, Cogent already works with dozens of Fortune 1000 companies, including Upwind Security, Alteryx, and CSC Generation Holdings

2

. The founding team brings deep expertise: Edupuganti and co-founder Geng Sng came from Abnormal Security, where Sng built the ML fraud detection system protecting half the Fortune 500. Third co-founder Thanos Baskous led infrastructure at Coinbase, handling large-scale vulnerability management

1

. The current team includes hires from Google's Gemini/DeepMind, Tesla, and Stripe, and already runs its platform in production across large Fortune 500 enterprise environments—traction Motamedi calls "incredibly rare" for a company at this stage

1

. Cogent's timing aligns with watershed moments like Log4j, the massive 2021 security flaw that exposed how enterprises struggled even to locate their exposure. "Most instances of Log4j are not remediated," Edupuganti noted, highlighting a gap he expects to widen as zero-days proliferate

1

.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo