Vulnerabilities found by Fortress MSSP research, published after coordinated disclosure
These advisories cover vulnerabilities Fortress MSSP identified in third-party software. We report to the vendor first, request a CVE identifier from the relevant CNA, and publish only after the vendor has shipped a fix or the coordinated-disclosure window has elapsed. Each advisory states its own timeline in full, including what the vendor did and when.
CVE identifiers on this page
Fortress MSSP LLC is not a CVE Numbering Authority. Identifiers referenced here were assigned by the relevant CNA — MITRE, or GitHub Security Advisories — in response to our coordinated-disclosure reports. We do not assign, reserve, or issue CVE IDs, and we do not issue CVEs for our own products.
This page is outbound only — findings we reported in other vendors' software. It is not our own vulnerability disclosure policy and does not describe the security of Fortress MSSP systems.
To report a vulnerability in a Fortress MSSP web property, see our responsible disclosure policy or /.well-known/security.txt. We do not operate a paid bug bounty programme.
The same research discipline applied to your environment.
Penetration Testing