generated: '2026-09-04' method: searched source: https://www.xylem.com/en-us/about/cybersecurity/incident-response/ note: >- probe-security-programs.py reported vdp=none because Xylem serves no /.well-known/security.txt on any host — the one security.txt reachable under a Xylem hostname belongs to Atlassian Statuspage, not to Xylem (see well-known/xylem-well-known.yml). The programme is nonetheless real and first-party; it is published as prose under www.xylem.com/en-us/about/cybersecurity/ and was read there on 2026-09-04. This artifact is hand-written from those pages. program: Xylem Product Security Incident Response Team (PSIRT) policy_type: Coordinated Vulnerability Disclosure (CVD) policy_url: https://www.xylem.com/en-us/about/cybersecurity/incident-response/ contact_url: https://www.xylem.com/en-us/about/cybersecurity/contact/ advisories_url: https://www.xylem.com/en-us/about/cybersecurity/security-advisories/ contacts: - method: email value: security@xylem.com note: Primary reporting address named on the cybersecurity contact page. - method: email value: product.security@xylem.com note: Alternate address for security researchers, customers, vendors and industry partners. encryption: supported: true method: PGP note: >- Xylem asks that confidential report content be PGP-encrypted and offers a downloadable Xylem PSIRT public key from the cybersecurity contact page. cna: is_cve_numbering_authority: true scope: Xylem products and technologies evidence: >- https://www.xylem.com/en-us/about/cybersecurity/incident-response/ — "Xylem is also an approved CVE Numbering Authority (CNA) for its products and technologies." bug_bounty: offered: false note: No bug bounty, safe-harbour statement, or HackerOne/Bugcrowd/Intigriti programme found. reporting_requirements: - Product name and version - Description of the potential vulnerability - Any special configuration required to reproduce the issue - Step-by-step instructions to reproduce - Proof of concept or exploit code, if available - Potential impact process: - step: 1 name: Acknowledge and triage detail: Xylem PSIRT acknowledges the report and begins triage. - step: 2 name: Risk assessment detail: >- Valid reports get a risk assessment based on technical severity, business impact and product. - step: 3 name: Remediation plan detail: >- Patches, updates, configuration changes, or compensating controls, chosen against the assessed risk. - step: 4 name: Coordinated disclosure detail: >- PSIRT coordinates disclosure through customer notifications, security advisories, or DHS CISA as appropriate. regulatory_alignment: - EU Cyber Resilience Act (stated alignment for intake, triage, remediation and disclosure) advisories: format: Numbered advisories, XPSA-- (product) and XSA-- (company/threat) count_published: 17 oldest: '2019-08-14' newest: '2024-11-20' feed: null feed_note: >- No RSS or Atom feed for advisories was found; subscription is via a marketing newsletter sign-up form on the same pages. sample: - id: XPSA-2024-015 date: '2024-11-20' title: Disclosure of Sensus wM-Bus Default Encryption Key - id: XPSA-2024-001 date: '2024-07-09' title: CVE-2024-6387 OpenSSH cve: CVE-2024-6387 - id: XPSA-2023-014 date: '2023-11-16' title: CVE-2023-46604 for Sensus RNI cve: CVE-2023-46604 - id: XPSA-2022-009 date: '2022-05-25' title: Sensus Analytics Login Service Vulnerability - id: XPSA-2021-004 date: '2021-12-16' title: AquaView Hardcoded Credentials Vulnerability memberships: - WaterISAC (Water Information Sharing and Analysis Center) - ISA Global Cybersecurity Alliance (ISAGCA) gaps: - >- No /.well-known/security.txt on xylem.com, www.xylem.com or any product host, so the programme is invisible to a machine even though it is well documented for a human. Publishing an RFC 9116 file naming security@xylem.com, the CVD policy URL and the PSIRT PGP key would make it discoverable at zero cost. - No machine-readable advisory feed (RSS/Atom/CSAF/VEX) alongside the advisory list.