Where video vendors publish security advisories
Thirteen major video-security vendors: whether each is a CVE Numbering Authority, where its advisories actually live, and whether those advisories carry CVE identifiers at all. Observed 5 September 2026.
Buyers are routinely told to "check the vendor's security advisories". This page is what happens when you try. Nine of the thirteen are CNAs, which the CVE Program's own machine-readable roster settles definitively — on 5 September 2026 that roster held 544 organisations, the highest identifier issued being CNA-2026-0062. The other four are not, and what that means differs sharply between them.
Two of the registered advisory URLs in the CVE Program's own records no longer resolve to an advisory index. One redirects to a login wall; the other now lands on a generative-AI search box. Both were checked on 5 September 2026.
The directory
| Vendor | CNA | Advisories | CVE IDs shown |
|---|---|---|---|
| Axis Communications | CNA-2021-0014 | advisory page | yes |
| Hikvision | CNA-2018-0002 | advisory page | yes |
| Dahua | CNA-2017-0014 | advisory page | yes |
| Hanwha Vision | CNA-2023-0043 | advisory page | yes |
| IQSIGHT (formerly Bosch Video Systems) | CNA-2026-0039 | advisory page | no |
| Robert Bosch GmbH | CNA-2019-0004 | advisory page | yes |
| Genetec | CNA-2023-0004 | advisory page | yes |
| Milestone Systems | CNA-2024-0007 | advisory page | yes |
| Uniview | CNA-2025-0048 | advisory page | yes |
| VIVOTEK | not a CNA | advisory page | yes |
| i-PRO | not a CNA | advisory page | yes |
| Avigilon (Motorola Solutions) | not a CNA | advisory page | no |
| Verkada | not a CNA | none found | no |
What CNA status does and does not tell you
A CVE Numbering Authority can assign CVE identifiers within its own scope. It means the vendor has invested in a disclosure process and that its vulnerabilities are more likely to reach NVD with usable product data. It does not mean the vendor's products are more secure, and it does not mean every vulnerability in them gets an identifier.
The scopes make that last point concrete. They disagree with each other on the single question that matters most for a long-lived estate — whether a discontinued product can receive a CVE at all:
| Vendor | Registered scope, verbatim |
|---|---|
| Axis Communications | All products of Axis Communications AB including end-of-life/end-of-service products. |
| Hikvision | Hikvision products. |
| Dahua | Dahua consumer Internet of Things (IoT) products, excludes End-of-Life products. |
| Hanwha Vision | Hanwha Vision products and solutions only, including end-of-life (EOL). |
| IQSIGHT (formerly Bosch Video Systems) | All IQSIGHT (formerly Bosch Building Technology - Video Systems) products including end-of-life products. |
| Robert Bosch GmbH | Bosch products (non-video business after the Video Systems divestment). |
| Genetec | Genetec hosted services and vendor products. |
| Milestone Systems | Supported Milestone XProtect products. |
| Uniview | Zhejiang Uniview Technologies products. |
Dahua's scope excludes end-of-life products outright. Milestone's covers supported XProtect products. Axis and Hanwha Vision both include end-of-life explicitly, and IQSIGHT inherited that wording for the former Bosch video line. For an estate where the average device is older than the support window, the vendors that exclude EOL will systematically produce fewer public vulnerabilities — and the products most likely to be exploited are the ones least likely to be catalogued.
Not being a CNA is not one thing
The four vendors without CNA status are in materially different positions, and lumping them together would be the easy mistake.
i-PRO has CVE coverage through JPCERT/CC, the Japanese national coordinator, which assigns identifiers for its products. That is a different route to the same outcome, not an absence of one.
VIVOTEK publishes advisories and lists CVE identifiers for its recent ones, after a gap of more than four years in which it published nothing.
Avigilon publishes 216 advisories inside its product documentation with no CVE identifier on any of them, keyed instead to internal ticket numbers. The advisories exist and are detailed; they simply cannot be matched against a vulnerability scanner's output.
Verkada has no discoverable advisory page at all.
Vendor by vendor
Axis Communications
- CNA
- CNA-2021-0014 — since April 2021
- CNA scope
- All products of Axis Communications AB including end-of-life/end-of-service products.
- Advisories
- https://help.axis.com/en-us/security-advisories
- Lifecycle
- published support model
- Firmware access
- open
Publishes CVE identifiers and CVSS severities on a fixed future disclosure date, before the fix and before technical detail. On 2026-09-05 its registry listed CVE-2026-13312 at CVSS 9.9 for AXIS Camera Station with released version "TBA" and a stated external disclosure date of 10 November 2026.
Observed problem. The CNA scope covers end-of-life products, but the Vulnerability Management Policy puts reports on products in the "Discontinued product. Online support only" phase out of scope. Supported software is typically covered for three years after the discontinuation announcement.
Hikvision
- CNA
- CNA-2018-0002
- CNA scope
- Hikvision products.
- Advisories
- https://www.hikvision.com/en/support/cybersecurity/security-advisory/
- Firmware access
- open
The public advisory index lists 30 advisories on page 1 of 2 and shows no publication date for any of them; dates exist only inside each advisory page. The 2026-07-22 advisory covers five CVEs with per-CVE credit: CVE-2026-57599 (6.6), CVE-2026-57600 (7.5), CVE-2026-61390 (7.7), CVE-2026-61391 (7.2) and CVE-2026-61392 (5.3).
Observed problem. The disclosure-policy URL Hikvision registered with the CVE Program is served behind bot mitigation and does not reliably return readable content to automated clients. We could not read it. The Internet Archive captured it with HTTP 200 on 2026-08-28; we make no claim about why an automated fetch fails.
Dahua
- CNA
- CNA-2017-0014
- CNA scope
- Dahua consumer Internet of Things (IoT) products, excludes End-of-Life products.
- Advisories
- https://www.dahuasecurity.com/aboutUs/trustedCenter/trustworthy
Process, advisory list and notice list share one URL behind in-page tabs; the advisory list runs to seven pages. Most recent entry on 2026-09-05: DHCC-SA-202606-001, dated 2026-06-10, covering CVE-2026-29114, CVE-2026-29115 and CVE-2026-29116.
Observed problem. Two defects. The CNA scope reads "consumer Internet of Things (IoT) products", which on its face does not cover the professional NVR/XVR line that Dahua's own advisories address. And the PGP fingerprint published for encrypted reports is malformed: 38 hexadecimal characters where an OpenPGP v4 fingerprint is 40.
Hanwha Vision
- CNA
- CNA-2023-0043 — since September 2023
- CNA scope
- Hanwha Vision products and solutions only, including end-of-life (EOL).
- Advisories
- https://www.hanwhavision.com/global/support/cybersecurity
- Firmware access
- open
The most explicit embargo commitment in this set: firmware and vulnerability details are withheld "until 90 days from receipt or until a date mutually agreed upon with the informant". Initial response within 2 business days; remediation and distribution plan within 10 business days.
Observed problem. The archive holds 19 documents. The three most recent are dated 2026-08-14, 2026-08-14 and 2026-07-29. The other 16 all carry the identical date 2026-04-06 despite covering CVEs from 2017 to 2024 — so the archive's dates cannot be read as disclosure dates.
IQSIGHT (formerly Bosch Video Systems)
- CNA
- CNA-2026-0039
- CNA scope
- All IQSIGHT (formerly Bosch Building Technology - Video Systems) products including end-of-life products.
- Advisories
- https://www.iqsight.com/
- Firmware access
- open
Bosch's video-security business now has a CNA separate from Robert Bosch GmbH, rooted under ENISA rather than CISA ICS, with contact psirt@iqsight.com. Announced as a rebrand of Bosch Video Systems on 2026-02-19; commits to "a minimum of five years of security support".
Observed problem. The advisory index carries 11 advisories under three incompatible identifier schemes at once — IQSIGHT-SI-2026-nnnn, KSA-254356, and eight legacy BOSCH-SA-nnnnnn-BT entries. No advisory shows a publication date, and the index's own severity counters disagree with its row count.
Robert Bosch GmbH
- CNA
- CNA-2019-0004
- CNA scope
- Bosch products (non-video business after the Video Systems divestment).
- Advisories
- https://psirt.bosch.com/
Remains a CNA rooted under CISA ICS, contact psirt@bosch.com, and offers an RSS feed. Hanwha Vision publishes one too, under the name Hanwha Vision Cybersecurity (S-CERT) — between them the only two machine-readable advisory feeds found in this set.
Observed problem. Whether Bosch PSIRT continues to publish for video products now owned by IQSIGHT, or whether the two PSIRTs will diverge, is not stated on either site.
Genetec
- CNA
- CNA-2023-0004
- CNA scope
- Genetec hosted services and vendor products.
- Advisories
- https://www.genetec.com/resources/security-vulnerabilities-advisories
- Firmware access
- login required
Real advisories exist and each CVE record links to its own per-advisory page — CVE-2026-55727 (CVSS 7.5), CVE-2026-40619 (7.8) and CVE-2025-43027 (9.8) among them. Publishes S/MIME certificates at pki.genetec.com.
Observed problem. The advisory URL Genetec registered with the CVE Program is no longer an index. It redirects twice and lands on a generative-AI resource-hub search for the word "vulnerabilities", under a banner reading "This tool uses generative AI. Results may be incomplete." There are no ID, severity or date columns, and advisories are not separated from marketing articles. The pages exist; the index is gone.
Milestone Systems
- CNA
- CNA-2024-0007
- CNA scope
- Supported Milestone XProtect products.
- Advisories
- https://doc.milestonesys.com/en-US/bundle/sec1504_latest/page/milestone_security_advisory.html
- Firmware access
- login required
Policy states confirmation within two business days, triage within 15, patches targeted within two months for CVSS critical and three for high. It does not compensate researchers, and asks for 90 days before disclosure.
Observed problem. The advisory URL Milestone registered with the CVE Program redirects to an Azure AD B2C login. Advisories are in fact public elsewhere, at the documentation URL listed here. Both the patch and the document describing it sit behind the same identity tenant. The policy also states plainly that for CVSS medium and low, "Patches are not provided for already released products."
Uniview
- CNA
- CNA-2025-0048 — since 2025
- CNA scope
- Zhejiang Uniview Technologies products.
- Advisories
- https://en.uniview.com/Support/Cybersecurity/Security_Notice/
- Firmware access
- open
Observed problem. Became a CNA in 2025, but the entire public Security Notice page contains six items and the most recent actual vulnerability notice is dated 2024-06-14 — more than two years before this survey. The only 2026 item is a marketing document, the "UNIVIEW AND NIS 2 White Paper" of 2026-08-07.
VIVOTEK
- CNA
- Not a CVE Numbering Authority
- Advisories
- https://www.vivotek.com/en-US/resource/support/cybersecurity
Not a CNA. The archive holds 22 entries — 20 numbered advisories plus two undated 2016/2017 announcements. CVE identifiers appear in a separate column for the 2026 advisories (CVE-2026-43284, CVE-2026-1642, CVE-2026-6682 through CVE-2026-6688).
Observed problem. A gap of roughly four years and four months: after VVTK-SA-2022-01 of 9 March 2022, the next advisory is dated 15 July 2026. The three 2026 entries carry mutually inconsistent identifiers — VVTK-SA-20260701, VVTK-SA-202601 and VVTK-SA-2026-02 — and every advisory PDF is served from a raw Azure blob endpoint rather than from vivotek.com. No PGP key and no CNA statement appear on the page.
i-PRO
- CNA
- Not a CVE Numbering Authority
- Advisories
- https://i-pro.com/global/en/surveillance/vulnerability
Not a CNA, but its vulnerabilities are covered: CVE IDs for i-PRO products are assigned by JPCERT/CC — for example CVE-2026-34488 (CVSS 7.3, April 2026) and CVE-2025-36513 (CVSS 4.3). The practical effect is reliance on a national coordinator rather than a vendor CNA, which is a different thing from having no coverage.
Observed problem. Panasonic Holdings holds a CNA, but its scope covers Panasonic Group companies and does not reach i-PRO since the carve-out. The public advisory list is short — four advisories, oldest 2023-08-31. Policy states a response within 10 business days and status updates every one to three months.
Avigilon (Motorola Solutions)
- CNA
- Not a CVE Numbering Authority
- Advisories
- https://docs.avigilon.com/bundle/alta-video/page/MoreInfo/head-advisories.htm
Motorola Solutions is not a CNA and publishes no product security advisory index — only a vulnerability-submission page with no stated disclosure timeline and no bug bounty. Avigilon's advisories live inside product documentation: 216 entries from 2020 to 2026.
Observed problem. Zero CVE identifiers appear anywhere on that index. Advisories are keyed to internal ticket numbers under three legacy prefixes ("Alta Video — 2199", "Alta Video —1408", "Ava-551"/"Vaion-262"). The 2026 entries are overwhelmingly third-party dependency issues. We found no public advisory listing for the on-premise Avigilon Unity / Control Center line at all; whether one exists behind partner authentication is unknown.
Verkada
- CNA
- Not a CVE Numbering Authority
- Advisories
- No discoverable advisory page
Observed problem. The largest cloud-native vendor in this set is not a CNA and has no discoverable security-advisory page. Its "Vulnerability Disclosure Program" page renders no policy text of its own — the served HTML shows the body is a client-side Bugcrowd embed, so the programme's scope, timelines and safe-harbour wording could not be read.
Method and limits
CNA status is taken from the CVE Program's machine-readable partner roster, searched programmatically — not from vendor marketing claims, which are frequently vaguer. Every other field is an observation of what a named URL returned on 5 September 2026, made with a desktop browser user-agent.
Two limits worth stating. Pages that did not render for an automated client are recorded as unread, not as absent: Hikvision's registered disclosure policy is served behind bot mitigation and Verkada's disclosure text is a client-side third-party embed, and in both cases we report a failure to read rather than a failure to publish. And this survey describes disclosure practice only. It supports no conclusion about which vendor's products are more secure, and a reader who draws one from it has drawn it from the wrong evidence — a vendor that publishes more advisories is usually a vendor that looks harder.
Per-product vulnerability history for these vendors is catalogued on CameraRisk.