generated: '2026-07-22' method: searched probe: true source: https://hackerone.com/cmegroup notes: >- CME Group runs a public vulnerability disclosure program on HackerOne (verified live, HTTP 200, "Vulnerability Disclosure Policy"). No /.well-known/security.txt could be verified on cmegroup.com hosts — the corporate site sits behind bot protection (403) and dataservices.cmegroup.com returns an Incapsula challenge shell for the path. policy: - https://hackerone.com/cmegroup platform: HackerOne program_type: vulnerability-disclosure evidence: - source: https://hackerone.com/cmegroup kind: hackerone-program status: 200 keywords: [vulnerability disclosure] - source: https://www.cmegroup.com/.well-known/security.txt kind: security.txt status: 403 note: bot protection blocks anonymous verification