generated: '2026-09-13' method: searched source: https://www.hologic.com/security/coordinated-vulnerability-disclosure-policy source_http_status: 200 note: >- Found by search, not by probe. 0-working/probe-security-programs.py reported "vdp=none trust=none" for this slug because the policy is not at any conventional path and no security.txt points at it — it lives at /security/coordinated-vulnerability-disclosure-policy and is linked only from the Breast & Skeletal Products Cybersecurity hub and the site's main navigation. That is the single most fixable discoverability gap on Hologic's public surface: the program is real, staffed and documented, and a machine cannot find it. program: exists: true name: Coordinated Vulnerability Disclosure Policy url: https://www.hologic.com/security/coordinated-vulnerability-disclosure-policy published_by: Hologic, Inc. contact_email: CoordinatedVulnerability@hologic.com pgp_key: https://www.hologic.com/sites/default/files/PGP.txt pgp_key_http_status: 200 scope: >- "This Coordinated Vulnerability Disclosure Policy applies to all Hologic commercially available products and/or Hologic digital assets owned, operated, or maintained by Hologic." Products owned or operated by other companies are out of scope. response_commitment: >- Hologic states it will "respond to your report promptly, and work with you to understand and validate your report" and will "strive to keep you informed about the progress of a vulnerability as it is processed." No numeric SLA is published. cve_program: true cve_note: Hologic references the CVE Program in its disclosure handling. safe_harbor_stated: false bug_bounty: false bounty_platform: null standards_named: [] standards_note: >- The policy does not cite ISO/IEC 29147 or ISO/IEC 30111 by name, though its structure (expectations of the researcher, commitments from the vendor) follows the coordinated disclosure shape those standards describe. security_txt: served: false probed: - url: https://www.hologic.com/.well-known/security.txt status: 404 - url: https://support.hologic.com/.well-known/security.txt status: 401 - url: https://www.hologic.co.uk/.well-known/security.txt status: 404 - url: https://www.endomag.com/.well-known/security.txt status: 404 remedy: >- Serve /.well-known/security.txt (RFC 9116) on hologic.com with Policy: https://www.hologic.com/security/coordinated-vulnerability-disclosure-policy, Contact: mailto:CoordinatedVulnerability@hologic.com and Encryption: https://www.hologic.com/sites/default/files/PGP.txt — every field already exists. advisories: published: true location: https://www.hologic.com/support/usa/breast-skeletal-products-cybersecurity location_http_status: 200 format: dated prose entries with linked PDF customer technical bulletins recent: - id: CVE-2023-4863 subject: libwebp heap buffer overflow date: '2023-10-12' - id: MOVEit Transfer subject: Progress MOVEit Transfer vulnerabilities (CVE-2023-35036 and related) date: '2023-07-14' - id: CTB-01038 subject: PTC Axeda Agent and Axeda Desktop Server vulnerabilities date: '2022-03-15' - id: CTB-00996 subject: Apache Log4j vulnerability risk mitigation date: '2021-12-16' - id: ransomware-alert subject: Ransomware alert to healthcare customers date: '2020-10-30' machine_readable: false machine_readable_note: >- No CSAF, VEX, RSS or JSON advisory feed. Advisories are hand-written HTML blocks plus linked PDFs, so a downstream SBOM or vulnerability-management tool cannot consume them. related: - support/usa/Breast-Skeletal-Products-Cybersecurity/MDS2-forms (per-product MDS2 security disclosure forms) - support/usa/Breast-Skeletal-Products-Cybersecurity/Cybersecurity-Reports-Best-Practices - support/usa/Breast-Skeletal-Products-Cybersecurity/Validated-Patches (validated Microsoft monthly critical patch releases) - support/usa/Breast-Skeletal-Products-Cybersecurity/Antivirus-Guides