generated: '2026-08-29' method: searched probe: true source: https://cvd.abbvie.com/ note: >- AbbVie runs a Coordinated Vulnerability Disclosure (CVD) process on its own host at cvd.abbvie.com, scoped to Medical Devices and Software as a Medical Device — not to a web/API bug bounty. Submissions go through a web form; AbbVie commits to acknowledging receipt within 5 business days, evaluating and attempting to reproduce the report, and publishing a notification on the CVD page when it determines disclosure is warranted. No security.txt is served (cvd.abbvie.com answers /.well-known/security.txt with the same 55,923-byte SPA shell as /), and hackerone.com/abbvie returns 404 — there is no bug bounty. policy: - https://cvd.abbvie.com/ submission_form: https://cvd.abbvie.com/vulnerability-submission contact: [] bug_bounty: false security_txt: false scope: - Medical Devices - Software as a Medical Device out_of_scope: - Technical support for AbbVie products - Adverse Events and Product Quality Complaints (call 844-663-3742 / abbviemedinfo.com) response_commitments: acknowledgement: 5 business days disclosure: Published on cvd.abbvie.com when AbbVie determines disclosure is warranted evidence: - source: https://cvd.abbvie.com/ kind: disclosure-page http_status: 200 fetched: '2026-08-29' - source: https://cvd.abbvie.com/vulnerability-submission kind: submission-form http_status: 200 fetched: '2026-08-29' - source: https://hackerone.com/abbvie kind: bug-bounty-probe http_status: 404 fetched: '2026-08-29' - source: https://cvd.abbvie.com/.well-known/security.txt kind: security-txt-probe http_status: 200 soft_404: true fetched: '2026-08-29'