ISG Software Research Analyst Perspectives

Cisco Anteres Advances Continuous Vulnerability Operations

Written by Jeff Orr | Sep 2, 2026, 9:59:59 AM

Enterprise security teams have access to extensive vulnerability intelligence but still struggle to determine where known flaws exist across large and changing software environments. Point-in-time assessments, manual code reviews and selective scanning cannot provide the coverage or frequency required as applications, dependencies and threats change. Artificial intelligence can accelerate this work, although concerns about source-code confidentiality, computing costs and output accuracy have limited adoption. Smaller, task-specific models create an opportunity to apply AI within enterprise infrastructure while retaining control of sensitive information. In the latest ISG Market Lens Cybersecurity Study, continuous threat detection and response is the clearest top priority for enterprise security leaders. It draws the strongest combined ranking of security concerns and appears as respondents’ most frequently named first choice. Cisco’s introduction of Antares demonstrates how specialized models can support a more continuous approach to vulnerability operations.

Cisco introduced Antares as a family of open-weight small-language models designed to localize known vulnerabilities within source-code repositories. The initial Antares-350M and Antares-1B models accept a vulnerability description, explore a repository and produce a ranked list of files likely to contain relevant code. The models also provide an exploration trace that security professionals can review. Cisco positions Antares as a focused alternative to using frontier models for every vulnerability investigation. Its benchmark testing indicates the models can outperform several larger open- and closed-weight models for vulnerability localization while requiring fewer computing resources. Local deployment also permits source code to remain within the organization’s infrastructure.

The open-weight approach expands the opportunity beyond a discrete Cisco product. Managed security service providers, security consultancies, systems integrators and software providers can incorporate Antares into vulnerability assessments, secure code reviews, remediation planning and managed application security workflows. Cisco can benefit from greater adoption of AI-assisted security practices across its partner ecosystem while creating connections to its broader security portfolio, specifications and services. Enterprises, however, should evaluate Antares based on its operational contribution rather than its relationship to a single provider’s platform.

Antares addresses vulnerability localization, which is only one stage of the vulnerability management process. It does not confirm that a vulnerability is exploitable, calculate its business impact, establish remediation priority or correct the affected code. Enterprises will need to combine model output with software composition analysis, static and dynamic application security testing, vulnerability intelligence, asset context and professional review. Application security, vulnerability management, software engineering, platform engineering and governance teams should participate in evaluation and operating-model design.

The strongest use cases will involve organizations with extensive proprietary source code, regulated data-handling requirements or application portfolios too large to assess consistently with frontier models. Local execution can reduce the risk associated with transferring source code to an external model service. Lower inference requirements can also make repeated analysis economically practical across more repositories. These characteristics may expand AI-assisted vulnerability operations to public-sector organizations, universities, regulated enterprises and security teams with limited budgets or infrastructure.

ISG Research asserts that by 2029, one-half of enterprises with large software portfolios will shift from periodic vulnerability assessments to continuous vulnerability operations, improving response to newly disclosed flaws.

Open-weight availability does not eliminate operational responsibility. Enterprises or service providers must secure repository access, manage model versions, monitor infrastructure, validate findings and retain audit evidence. Testing model performance against representative languages, architectures and vulnerability categories is critical. Cisco’s results are based on its benchmark and evaluation methodology. Enterprise performance may vary according to repository complexity, code quality and the information available in each vulnerability description.

ISG Research recommends that enterprises evaluate specialized security models through controlled pilots rather than broad production deployment. Assess localization accuracy, false-positive rates, analyst time, processing cost, repository coverage and integration with development and remediation workflows. Determine whether the model reduces the time between vulnerability disclosure and informed action.

Cisco Antares represents an emerging class of specialized security AI that can make vulnerability analysis more private, economical and repeatable. Its market significance rests less on standalone model performance than on its potential to support continuous vulnerability operations. Enterprises should regard Antares as an investigation accelerator within an integrated application security program, with human validation and established security controls remaining essential.

Regards,

Jeff Orr