Security Bulletins
Every advisory we’ve ever issued, archived in public
If we find a security issue, we publish it. Severity, affected components, customer impact, time-to-resolution. Subscribe to receive new advisories within 60 minutes of publication.
Critical (12 mo)
1
0 exploited in our deployment
High + Medium (12 mo)
3
All patched within SLA
Median TTR
1h 27m
Critical & High advisories
Subscribers
2,140
Security teams + auditors
| ID | Date | Title | Severity |
|---|---|---|---|
| ADM-2026-014 | 2026-06-18 | Race condition in pacing webhook replay | Medium |
| ADM-2026-013 | 2026-05-29 | Subprocessor change — DNS provider added | Informational |
| ADM-2026-012 | 2026-05-11 | Privilege escalation in legacy invite link | High |
| ADM-2026-011 | 2026-04-22 | Information disclosure via verbose error | Low |
| ADM-2026-010 | 2026-03-08 | Dependency: critical RCE in image library | Critical |
| ADM-2026-009 | 2026-02-14 | Audit log gap during failover | Medium |
ADM-2026-014 · 2026-06-18
Race condition in pacing webhook replay
Affected: Webhook delivery v3.2.x
Customer impact
No data loss; <0.001% of replayed events could be processed twice; idempotency keys prevented double posting.
Resolution · TTR 4h 12m
Patched 18 Jun, customers on managed plan auto-upgraded.
ADM-2026-013 · 2026-05-29
Subprocessor change — DNS provider added
Affected: Edge DNS resolution
Customer impact
No customer data touched; informational change to subprocessor register.
Resolution · TTR n/a
Published on /legal/subprocessors with 30-day notice.
ADM-2026-012 · 2026-05-11
Privilege escalation in legacy invite link
Affected: Workspace invites issued before 2026-04-01
Customer impact
Revoked invites could be reused within a 7-minute window. No production accounts affected per audit log.
Resolution · TTR 2h 41m
Invites rotated, TTL hardened to 60s, monitoring rule added.
ADM-2026-011 · 2026-04-22
Information disclosure via verbose error
Affected: Public docs search
Customer impact
Internal stack trace returned on malformed query; no customer data exposed.
Resolution · TTR 55m
Errors sanitised, regression test added.
ADM-2026-010 · 2026-03-08
Dependency: critical RCE in image library
Affected: Logo upload pipeline
Customer impact
Not exploitable in our deployment (sandboxed, no shell); patched as precaution.
Resolution · TTR 38m
Upgraded library, deployed in 38 minutes.
ADM-2026-009 · 2026-02-14
Audit log gap during failover
Affected: EU-west-2 region
Customer impact
31-minute gap in audit log streaming; events were replayed from buffer with no loss.
Resolution · TTR 1h 14m
Buffer flush hardened; replay verified by auditor.