VideoCybersecurity

A reference for securing video infrastructure

Which video vendors publish security advisories

What the CVE Program's machine-readable partner list says about video vendors, and what a vendor's own advisory page says after you actually try to read it.

Published 5 September 2026Sources 21

Vendor trust pages are marketing surfaces, and we work with MITRE is not a checkable claim. The CVE Program publishes the answer as a file. CNAsList.json backs the partner list on cve.org, and on 5 September 2026 it held 544 organizations, the highest allocated identifier being CNA-2026-0062. We searched all 544 records for axis, hikvision, dahua, hanwha, bosch, avigilon, motorola, genetec, milestone, vivotek, i-pro, ipro, verkada, uniview and zhejiang.

Nine of the twelve video-security vendors we examined are CNAs. Three are not. Verkada, checked as a thirteenth name, returns zero matches as well.

The roster, as of 5 September 2026#

VendorCNARootWhere advisories are publishedCoordinated-disclosure policy
Axis CommunicationsCNA-2021-0014MITREhelp.axis.comYes — 2-day response, 10-day triage, quarterly dates
HikvisionCNA-2018-0002not recorded here1hikvision.comPolicy URL registered; body not retrievable
DahuaCNA-2017-0014not recorded here1dahuasecurity.comYes — receipt in 2 days, conclusion in 7
Robert Bosch GmbHCNA-2019-0004CISA ICSpsirt.bosch.comNot assessed here
IQSIGHT B.V.CNA-2026-0039ENISAiqsight.comYes — PGP or a Hackrate form
Hanwha VisionCNA-2023-0043MITREhanwhavision.comYes — explicit 90-day embargo
GenetecCNA-2023-0004MITREIndex gone; per-advisory pages existReports to security@genetec.com
Milestone SystemsCNA-2024-0007MITREdoc.milestonesys.com; registered URL login-gatedYes — 90 days, PDF
UniviewCNA-2025-0048MITREglobal.uniview.comYes — "usually within seven business days"
Motorola Solutions / AvigilonNodocs.avigilon.com, Alta Video onlySubmission page; no timeline, no bounty
VIVOTEKNovivotek.comEmail or Zendesk; no PGP
i-PRONo — JPCERT/CC assignsi-pro.com PSIRTYes — 10 business days, updates every 1–3 months
VerkadaNoNo advisory index foundBugcrowd embed; policy text not readable

What registration actually buys#

One thing: the authority to allocate a CVE ID for your own products without asking a coordinator. Nothing in it obliges a vendor to publish.

Uniview is the cleanest proof. It joined the roster in 2025 as CNA-2025-0048, and its entire public Security Notice page holds six items with no pagination control. The most recent actual vulnerability notice is dated 14 June 2024. The one 2026 item is a marketing document, the "UNIVIEW AND NIS 2 White Paper" of 7 August 2026.

Axis does the opposite. Its registry lists CVE IDs and CVSS severities before the fix ships and before any technical detail is public. On 5 September 2026 it carried CVE-2026-13312 at 9.9 Critical for AXIS Camera Station, released version "TBA", with the note that the CVE "will be externally disclosed on 10 November 2026". CVE-2026-13387 (3.5) and CVE-2026-12964 (8.0) carry the same date — the second Tuesday of November, which is the quarterly cadence the Axis Vulnerability Management Policy commits to, alongside first response within 2 business days, triage within 10, and a four-week resolution target for anything scoring 7.0 to 10.0. It tells a defender that an unpatched 9.9 exists in something they own, two months before the details land.

The scopes disagree, and so do the scores#

CNA scopes disagree about whether an end-of-life product can receive a CVE at all: Axis and Hanwha include EOL products, Dahua excludes them, Milestone covers only supported XProtect. That disagreement, and the two internal contradictions it produces at Dahua and at Axis, is worked through in end-of-life cameras and cyber risk.

The severities are not comparable either. Axis's policy commits to CVSS v4.0. Dahua states that it "adopts CVSSv3". Uniview scores with CVSSv3.1 using Base and Temporal Metrics, which move a published number as exploit maturity and remediation level change. Hikvision's 22 July 2026 advisory scores under v3.1 and publishes the vector. Four vendors, three standards. Sort a multi-vendor register by severity and you are sorting mixed units: a 7.5 carrying a v3.1 temporal component and a 7.5 produced by v4.0 are different measurements wearing the same number.

What the policies exclude#

Milestone's policy is the most specific document in the set, and most of the specificity is exclusion. Out of scope: products in the "Terminated" state, third-party plug-ins and integrations, DLL hijacking and sideloading on Windows, all Microsoft Windows and third-party Windows software, and anything requiring highly privileged account permissions as a prerequisite. Inside scope, it triages in 15 business days and targets two months for CVSS 9.0–10.0, three months for 7.0–8.9. For medium and low, "Patches are not provided for already released products" — the fix rides a scheduled upcoming release, which for a deployed estate means the next upgrade project. "Milestone does not compensate researchers" is in the same document.

Hikvision's index showed thirty advisories on the first of two pages; we did not enumerate the second, so the total is unknown. None of the thirty carried a publication date. A regex sweep across the rendered page returned exactly one date string, and that was inside a teaser. Dates exist only inside each advisory, so cadence cannot be measured without opening every item.

IQSIGHT's index carries 11 advisories under three incompatible identifier schemes at once: IQSIGHT-SI-2026-0601 and -0528; KSA-254356 ("BVMS Unrestricted SSH Resource Consumption"); and eight legacy BOSCH-SA-nnnnnn-BT entries, one of them "Unauthenticated Information Leak in Bosch IP Cameras". No dates on any of them. The severity filters total 10 while the table header reads "Showing 11 of 11 advisories". Everything is served as PDF.

That index matters because of what moved this year. IQSIGHT B.V. holds CNA-2026-0039, scoped to "All IQSIGHT (formerly Bosch Building Technology - Video Systems) products including end-of-life products", rooted under ENISA. Robert Bosch GmbH remains CNA-2019-0004, rooted under CISA ICS. Bosch-branded video therefore moved from a German vendor under a US root to a Dutch vendor under an EU root; IQSIGHT was announced on 19 February 2026 as the rebrand of Bosch Video Systems. This is not a completed handover. Bosch PSIRT is still live and still shipping — BOSCH-SA-223618, 31 August 2026 — and neither site says who owns video advisories from here. We could not date IQSIGHT's most recent advisory, or establish whether it has issued any CVE under its new authority.

Genetec's registered advisory URL redirects twice and lands on a generative-AI resource search for the word "vulnerabilities", under a banner warning that "Results may be incomplete." The advisories are in there — CVE-2026-55727 (7.5), CVE-2025-43027 (9.8 Critical, ALPR Manager role) — each reachable from its own CVE record. The index is gone, not the content.

Milestone's registered URL redirects to an Azure AD B2C login. The advisories are public elsewhere, at doc.milestonesys.com: 32 topics, CVE-2026-3014 the most recent, last updated 15 July 2026. The path is case-sensitive, and the capitalised variant that search engines index returns 404.

Hanwha's archive holds 19 documents. Sixteen carry the identical date 2026.04.06 while covering CVEs from 2017 through 2024, CVE-2017-7912 and CVE-2021-44228 among them. That is a republication stamp, not a publication date, and anyone reconstructing Hanwha's disclosure history from it will get it wrong.

Avigilon's index holds 216 entries grouped by year from 2020 to 2026 — 43 in 2025, 45 in 2024 — keyed to internal ticket prefixes such as "Alta Video — 2199", "Ava-551" and "Vaion-262", with zero CVE identifiers anywhere on the index page. We did not open individual topics, so whether CVE IDs appear inside them is unestablished, and we found no advisory listing at all for the on-premise Avigilon Unity / ACC line.

Dahua's reporting channel has two defects. The PGP fingerprint it publishes for encrypted reports, 61769A82F67E062CA46C19A6DEA2F8C6068E4B, is 38 hexadecimal characters where an OpenPGP v4 fingerprint is 40; the stated Key ID 0xC6068E4B sits at the tail of the string, so two characters are missing from the middle and a researcher cannot verify key authenticity from it. The address disagrees with itself too: the CNA record registers cybersecurity@dahuatech.com, the live PSIRT page says psirt@dahuatech.com, and we did not test which one is monitored.

Absent from the roster#

i-PRO is not a CNA. Its CVEs are assigned by JPCERT/CC — CVE-2026-34488 (IP Setting Software, 7.3) and CVE-2025-36513 (WV-X/S/U network cameras, 4.3) both carry the jpcert assigner. Panasonic Holdings holds a CNA scoped to Panasonic Group companies, which stopped reaching i-PRO at the carve-out, so coverage runs through a national coordinator instead. The public list is short: four advisories, the oldest 31 August 2023.

VIVOTEK is not a CNA and claims none, yet its archive runs to 22 entries and lists CVE IDs for its 2026 advisories in a dedicated column (CVE-2026-43284, CVE-2026-1642, CVE-2026-6682 through -6688). It also contains a gap of four years and four months: after VVTK-SA-2022-01 in March 2022, nothing until 15 July 2026. The three 2026 entries use three identifier formats — VVTK-SA-20260701, VVTK-SA-202601, VVTK-SA-2026-02 — and every PDF is served from a raw Azure blob endpoint rather than from vivotek.com.

Verkada is not a CNA and has no advisory page at all. Its "Vulnerability Disclosure Program" page renders no policy text of its own; the served HTML shows the body is a client-side component named ReportIssueBugcrowdEmbed. Its only security-notice surface is an incident and compliance log: the March 2021 unauthorised-access incident, a December 2021 Log4j statement, an ISO/IEC 27701 certification in September 2025. A vulnerability-management process has nothing there to subscribe to, and because the embed produced zero text nodes and no inline copy, we cannot describe what its programme promises a researcher either. See cloud video security.

Motorola Solutions publishes no advisory index at all — only a submission page asking for "reasonable time to investigate and mitigate", with no timeline and no bounty.

What we could not read#

Hikvision's registered disclosure-policy URL is served behind bot mitigation and did not return readable content to any automated client we used. We are not publishing a status code or a retry count, because we did not preserve the raw headers and response body that would make either checkable. We are not publishing a cause. So we cannot say whether that document states CNA status, timelines, safe-harbour language or an effective date. The Internet Archive captured the page with HTTP 200 on 28 August 2026, so it exists; we did not read it. Hikvision advisory content is reachable by other routes: its 22 July 2026 advisory, referenced by NVD, covers five CVEs — CVE-2026-57599 (6.6), CVE-2026-57600 (7.5), CVE-2026-61390 (7.7), CVE-2026-61391 (7.2) and CVE-2026-61392 (5.3) — across the DS-2CD, DS-2DE, DS-2DP and DS-2TD series, with credit assigned per CVE rather than shared.

Hanwha's "Long-Term Firmware Support Policy" PDF (V3.2, filename-dated 20250110) is an image-only scan with no extractable text. How many years Hanwha commits to, and whether the clock starts at end-of-production or end-of-sale, we cannot verify.

We did not probe /.well-known/csaf/ on any of these vendors. Bosch PSIRT offers RSS; we found no CSAF endpoint in this set, and that describes our fetches rather than the vendors.

What this survey does not tell you#

It measures disclosure practice. Nothing here supports a claim about product quality, and the two frequently invert: a vendor publishing 216 dated advisories is more legible than one publishing six, and legibility is not safety. Silence can mean a clean codebase or an unread inbox. This data does not separate them.

What it does support is procurement language. Ask for the CNA identifier rather than the claim, then read the registered scope against your refresh cycle. Check whether the advisory URL needs a login — Milestone's does, as do its firmware downloads, which puts the patch and the document describing it behind one identity tenant. Ask whether advisories carry dates and CVE identifiers, because Hikvision's index carries no dates, IQSIGHT's carries none either, and Avigilon's carries dates but no CVE IDs at all. For per-model history rather than per-vendor posture, camerarisk.com tracks published vulnerabilities device by device.

Notes

  1. Every CNA sits under a root. We recorded the root only where we read it from the partner record; Hikvision's and Dahua's we did not capture. An em-dash means the organisation is not a CNA.

Sources

  1. CNAsList.json — the data behind cve.org's List of Partners. CVE Program, fetched 2026-09-05
  2. Axis security advisories registry. Axis Communications, observed 2026-09-05
  3. Axis Vulnerability Management Policy. Axis Communications, fetched 2026-09-05
  4. Security Advisory — Cybersecurity. Hikvision, observed 2026-09-05
  5. Vulnerability Disclosure Policy (registered CNA policy URL). Hikvision, not retrievable 2026-09-05
  6. Security Vulnerabilities in Some Hikvision Cameras. Hikvision, 2026-07-22
  7. Dahua PSIRT — Trusted Center. Zhejiang Dahua Technology, observed 2026-09-05
  8. Cybersecurity — Security Vulnerability Disclosure Policy. Hanwha Vision, observed 2026-09-05
  9. Cybersecurity — Vulnerability Report archive. Hanwha Vision, observed 2026-09-05
  10. Product Security and Advisory Center. IQSIGHT, observed 2026-09-05
  11. Introducing IQSIGHT: A New Intelligence-First Video Security Brand. PR Newswire, 2026-02-19
  12. Bosch PSIRT security advisories. Robert Bosch GmbH, observed 2026-09-05
  13. Milestone Security Advisory — CVE-2026-3014. Milestone Systems, last updated 2026-07-15
  14. XProtect VMS Vulnerability Management Policy (PDF). Milestone Systems, undated
  15. Trust and cybersecurity resources. Genetec, observed 2026-09-05
  16. Security Notice. Uniview, observed 2026-09-05
  17. Cybersecurity advisory archive. VIVOTEK, observed 2026-09-05
  18. PSIRT security advisories. i-PRO, observed 2026-09-05
  19. Alta Video security advisories. Avigilon, last updated 2026-08-19
  20. Vulnerability Disclosure Program. Verkada, observed 2026-09-05
  21. Security updates. Verkada, observed 2026-09-05