Wire · regulatory
CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 16 July 2026 · Fusion42 review
CISA published coordinated vulnerability disclosure guidance for software vendors, drawing directly from its own May 2026 incident where a researcher's nine emails went unanswered and credentials leaked via public GitHub. The guidance maps CISA's operational failures—undefined reporting channels, no cloud incident playbook, slow key rotation—into concrete recommendations: security.txt files, 2-3 day acknowledgement windows, separated disclosure/support channels, and safe-harbour language for researchers.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
If you sell software to US federal agencies or the EU, you now have a public playbook for how to accept vulnerability reports—and CISA has just made it a compliance requirement. The path from researcher to fix that took CISA nine unanswered emails is now the thing you cannot do.
◆ Coverage
1 source · 16 Jul 2026
◆ Related on Wire
◆ Topics