generated: '2026-09-05' method: searched probe: true policy: - https://www.cohesity.com/trust/security-profile/ contact: - https://www.cohesity.com/forms/contact/security/ bug_bounty: null bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti program was found for Cohesity. Reports are taken through a first-party contact form, not a bounty platform. security_txt: false security_txt_note: >- /.well-known/security.txt was probed on cohesity.com, www.cohesity.com, developer.cohesity.com, developers.cohesity.com, docs.cohesity.com, api.cohesity.com and helios.cohesity.com. Every host returned 404 or an SPA shell - Cohesity publishes no RFC 9116 document. This is the cheapest fix available to them: the disclosure program already exists, it is just not machine-discoverable. advisories: url: https://github.com/cohesity/SecAdvisory format: One markdown file per advisory in a public GitHub repository. identifiers: [CVE, 'COH-YYYY-NNNN'] examples: [COH-2026-0001, COH-2026-0002, CVE-2023-33295, CVE-2021-36795, CVE-2021-28123, CVE-2021-28124] last_updated: '2026-08-28' statement: >- "Customers, partners, and third-party researchers may report vulnerabilities in Cohesity products and services by contacting Cohesity Security." evidence: - {source: 'https://www.cohesity.com/trust/security-profile/', kind: disclosure-policy, http_status: 200} - {source: 'https://www.cohesity.com/forms/contact/security/', kind: security-contact, http_status: 200} - {source: 'https://github.com/cohesity/SecAdvisory', kind: advisory-registry, http_status: 200} - {source: 'https://www.cohesity.com/.well-known/security.txt', kind: security.txt, http_status: 404} maintainers: - FN: Kin Lane email: kin@apievangelist.com