OPSWAT Vulnerability Program
Help Strengthen Critical Infrastructure Security
The OPSWAT Vulnerability Program provides a responsible disclosure channel for security researchers to report vulnerabilities affecting eligible OPSWAT products, services, and websites. Through collaboration with the security community, we can identify, validate, and remediate issues quickly-helping our customers stay secure.
Report a Vulnerability
At OPSWAT, protecting critical infrastructure is our mission. We believe security is a shared responsibility and value the contributions of independent security researchers who help identify vulnerabilities before they can be exploited.
If you believe you have discovered a security vulnerability in an OPSWAT product or service, please submit your findings through My OPSWAT Portal.
This will redirect you to My OPSWAT Portal, where you can sign in or create an account before accessing the vulnerability submission form.

Program Scope
The Vulnerability Program* applies to eligible OPSWAT-owned products, cloud services, applications, and public-facing websites.
*Additional scope details may be provided within the submission portal.
In Scope | Out of Scope |
|---|---|
|
|
Responsible Disclosure Guidelines
To help us investigate and remediate issues efficiently, please:
Act in good faith to avoid privacy violations, data destruction, service disruption, or unauthorized access to customer information.
Test only against systems that are in scope for the program.
Provide sufficient detail to reproduce the vulnerability, including affected product versions, proof of concept, screenshots, logs, or other supporting evidence.
Give OPSWAT a reasonable opportunity to validate and remediate the issue before publicly disclosing details.
Immediately stop testing and notify OPSWAT if you encounter sensitive customer, employee, or proprietary data.
Duplicate reports, previously known issues, and findings that cannot be reproduced may not qualify.
Safe Harbor
OPSWAT supports responsible security research conducted in accordance with this policy. If you comply with the Vulnerability Program rules and act in good faith, OPSWAT will not pursue legal action against you for security research activities that:
- Are conducted within the defined scope of this program
- Do not intentionally disrupt services or systems
- Do not access, modify, or retain customer data beyond what is necessary to demonstrate the vulnerability
- Are promptly reported to OPSWAT through approved disclosure channels
Researchers are expected to comply with all applicable laws and regulations.

Vulnerability Severity
Eligible submissions may qualify for recognition based on severity, impact, exploitability, and report quality.
| Severity | Critical | High | Medium | Low |
|---|---|---|---|---|
| Example Impact | Remote code execution, authentication bypass, complete compromise | Significant privilege escalation, sensitive data exposure | Limited data exposure, security control bypass | Low-impact vulnerabilities with limited exploitability |
Submission Process
Submit Report
Submit your report through My OPSWAT Portal.
Receive Confirmation
PCI DSS, SOX, DORA, GDPR, and NYDFS require strong controls around malware prevention and data protection.
Validate and Triage
OPSWAT validates and triages the report.
Investigate and Remediate
Our security team investigates and develops remediation plans.
Receive Recognition
Qualified submissions may receive recognition.
Publish Security Advisory or CVE
When appropriate, OPSWAT publishes a security advisory or CVE.
Participant represents that they are not located in, ordinarily resident in, or acting on behalf of any person located in a jurisdiction subject to comprehensive U.S. sanctions and are not listed on any applicable U.S. government restricted party list.
Questions
For questions regarding the OPSWAT Vulnerability Program, responsible disclosure practices, or vulnerability reporting, please contact the OPSWAT Security Team at psirt@opswat.com.
Together, we can strengthen cybersecurity and help protect the world's critical infrastructure.





