Legal
Security Advisories
Last updated: September 14, 2026
This page is the public record of vulnerabilities that Invadel testers have discovered in third-party software and disclosed under the coordinated disclosure process in our Responsible Disclosure Policy. Each advisory lists the affected product and versions, the CVE ID once one is assigned, a CVSS severity, the disclosure timeline, and whether a fix is available.
Findings from client engagements are confidential under the engagement contract and are never published here. Advisories cover only commercial and open-source software that is not owned by a client, and they are published after the vendor has released a fix or the disclosure window in our policy has passed.
Published advisories
No advisories have been published yet. Advisories appear here once a vendor fix is available or the 90-day disclosure window has closed. Each entry will link to its CVE record on cve.org.
What each advisory contains
- Invadel advisory ID in the form INV-YYYY-NNN, and the CVE ID once assigned.
- Affected product and versions, as confirmed with the vendor or maintainer.
- Summary and impact: what an attacker can do, scored with CVSS.
- Timeline: the date the vendor was notified and the date of publication.
- Fix status: fixed, fix available, mitigation available, or unpatched.
- Credit to the tester who found it, with their consent.
Advisories describe the vulnerability and how to verify it. They do not include weaponized exploit code.
How disclosure works
The vendor or maintainer is notified privately first, through their published security contact, with reproduction steps. Publication follows the earliest of: the vendor releasing a fix, 90 days from the initial report, or evidence that the vulnerability is being exploited in the wild. Vendors acting in good faith on a fix can ask for an extension. The full process, including what we ask of vendors, is in the third-party section of the policy.
Contact
Vendors who have received a report from Invadel, researchers with questions about an advisory, and anyone who has found a vulnerability in Invadel’s own systems can reach the security team at info [at] invadel [dot] com. Reports about Invadel’s own systems are covered by the Responsible Disclosure Policy.