Cybersecurity

Reporting of Security Advisories

Vulnerability Reporting Process for ZAHORANSKY Products

ZAHORANSKY AG is committed to continuously improving the security of its products, systems and services. We welcome reports of potential vulnerabilities, as they contribute to product security. At psirt@zahoransky.com we provide a way to submit anonymous vulnerability reports in German or English. Our aim is a constructive dialogue that enables a Coordinated Vulnerability Disclosure.

The individual process steps are:

Report

A vulnerability is reported to ZAHORANSKY AG. Our cooperation does not require a non-disclosure agreement, and we do not take legal action against good-faith security research. The more detailed a report is, the faster and more precisely we can respond to it. Reports should include a product designation, the criticality of the potential vulnerability and steps to reproduce it. ZAHORANSKY AG observes the Traffic Light Protocol (TLP) version 2.0, described at https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/TLP/merkblatt-tlp.html.

Analysis

Incoming reports are reviewed by ZAHORANSKY AG for completeness and relevance. The reports are shared with the responsible individuals and departments, and we maintain regular contact with the person who submitted the report. Where necessary, authorities, CERTs or other partners are informed about the report.

Resolution

Together with the responsible departments, a solution is developed to address the vulnerability appropriately. If the reporter wishes, he or she will be kept informed about the progress of these activities. On request, the solution can be tested jointly.

Publication

The vulnerability is published on the ZAHORANSKY AG website at a mutually agreed point in time. The publication includes a description of the vulnerability, a severity rating as well as measures to remediate the vulnerability or minimise its risk. If this coordinated disclosure process has been followed, the discoverer of the vulnerability can be publicly credited.

Security Advisories

ID
Date
Title
CVSS Score
Products
Downloads
2026-002
August 4, 2026
Nummer 2
8,0

Z.PACK

2026-001
August 4, 2026
Nummer 1
5,5

Z.SWAN
Z.ORCA