Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT security engineering

Vulnerability disclosure

Also known as: Vulnerability reporting

German: Schwachstellenoffenlegung

In product security, vulnerability disclosure is the process of receiving reports about potential vulnerabilities in products or services and publishing information about confirmed vulnerabilities, their impact and their remediation to users. ISO/IEC 29147 gives requirements and recommendations for vendors.

  • Security engineering
  • OT security
  • Standards

In one sentence

Vulnerability disclosure covers receiving reports of vulnerabilities and publishing information about confirmed ones and their remediation to users.

Example

A robot manufacturer lists a security contact and a PGP key on its website, receives a report about a controller service, and later publishes an advisory describing the fix.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Product development: Vendors need a public, easy-to-find way to receive reports, for example a security contact page or a security.txt file on their website, and an internal process to triage them. ISO/IEC 30111 describes the internal vulnerability handling that follows.
  • Compliance: The Cyber Resilience Act (CRA) requires manufacturers to provide a contact address for reporting vulnerabilities and to share information about fixed vulnerabilities with users.
  • Operation: Operators and integrators who find vulnerabilities in supplier products should report them through these channels rather than publishing them.
  • Documentation: Product documentation, type labels or packaging and the website should point to the vulnerability reporting contact. Published information should be precise about affected versions and remediation and use the same product names as the manuals.

Vulnerability disclosure vs. coordinated vulnerability disclosure

Vulnerability disclosure is the general process of reporting and publishing. Coordinated vulnerability disclosure (CVD) adds the coordination among reporter, vendor and other parties so that publication follows the availability of a fix or mitigation.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: ISO/IEC 29147:2018, Information technology — Security techniques — Vulnerability disclosure

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!