Security Bulletins

Every advisory we’ve ever issued, archived in public

If we find a security issue, we publish it. Severity, affected components, customer impact, time-to-resolution. Subscribe to receive new advisories within 60 minutes of publication.

Critical (12 mo)

1

0 exploited in our deployment

High + Medium (12 mo)

3

All patched within SLA

Median TTR

1h 27m

Critical & High advisories

Subscribers

2,140

Security teams + auditors

IDDateTitleSeverity
ADM-2026-0142026-06-18Race condition in pacing webhook replayMedium
ADM-2026-0132026-05-29Subprocessor change — DNS provider addedInformational
ADM-2026-0122026-05-11Privilege escalation in legacy invite linkHigh
ADM-2026-0112026-04-22Information disclosure via verbose errorLow
ADM-2026-0102026-03-08Dependency: critical RCE in image libraryCritical
ADM-2026-0092026-02-14Audit log gap during failoverMedium

ADM-2026-014 · 2026-06-18

Race condition in pacing webhook replay

Affected: Webhook delivery v3.2.x

Medium

Customer impact

No data loss; <0.001% of replayed events could be processed twice; idempotency keys prevented double posting.

Resolution · TTR 4h 12m

Patched 18 Jun, customers on managed plan auto-upgraded.

ADM-2026-013 · 2026-05-29

Subprocessor change — DNS provider added

Affected: Edge DNS resolution

Informational

Customer impact

No customer data touched; informational change to subprocessor register.

Resolution · TTR n/a

Published on /legal/subprocessors with 30-day notice.

ADM-2026-012 · 2026-05-11

Privilege escalation in legacy invite link

Affected: Workspace invites issued before 2026-04-01

High

Customer impact

Revoked invites could be reused within a 7-minute window. No production accounts affected per audit log.

Resolution · TTR 2h 41m

Invites rotated, TTL hardened to 60s, monitoring rule added.

ADM-2026-011 · 2026-04-22

Information disclosure via verbose error

Affected: Public docs search

Low

Customer impact

Internal stack trace returned on malformed query; no customer data exposed.

Resolution · TTR 55m

Errors sanitised, regression test added.

ADM-2026-010 · 2026-03-08

Dependency: critical RCE in image library

Affected: Logo upload pipeline

Critical

Customer impact

Not exploitable in our deployment (sandboxed, no shell); patched as precaution.

Resolution · TTR 38m

Upgraded library, deployed in 38 minutes.

ADM-2026-009 · 2026-02-14

Audit log gap during failover

Affected: EU-west-2 region

Medium

Customer impact

31-minute gap in audit log streaming; events were replayed from buffer with no loss.

Resolution · TTR 1h 14m

Buffer flush hardened; replay verified by auditor.