← Back

Wire · regulatory

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance

Published

16 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at helpnetsecurity.com

Verified

Fusion42 · 16 July 2026 · Fusion42 review

CISA published coordinated vulnerability disclosure guidance for software vendors, drawing directly from its own May 2026 incident where a researcher's nine emails went unanswered and credentials leaked via public GitHub. The guidance maps CISA's operational failures—undefined reporting channels, no cloud incident playbook, slow key rotation—into concrete recommendations: security.txt files, 2-3 day acknowledgement windows, separated disclosure/support channels, and safe-harbour language for researchers.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you sell software to US federal agencies or the EU, you now have a public playbook for how to accept vulnerability reports—and CISA has just made it a compliance requirement. The path from researcher to fix that took CISA nine unanswered emails is now the thing you cannot do.

Coverage

1 source · 16 Jul 2026

Related on Wire

Topics

Cybersecurityvulnerability-disclosuresecurity-incident-responsecisa-guidancesecrets-scanningfederal-compliance