Skip to content

Commit ec35ffc

Browse files
rrobergerlxdev
andauthored
3/31/26 release branch (#3891)
* #3887 Add Blog @ VulnCon 2026 registration closing date * #3885 Add 4 new CNAs + Update 2 CNA's info * #3886 Add 1 new Blog @ 500+ CNAs milestone * Correct figure captions for centered italic text * npm update on 3/30/26 * SADP tag/button implementation --------- Co-authored-by: Roy Lane <rlane@mitre.org>
1 parent 7397474 commit ec35ffc

14 files changed

Lines changed: 918 additions & 322 deletions

File tree

package-lock.json

Lines changed: 293 additions & 290 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
322 KB
Loading

src/assets/data/CNAsList.json

Lines changed: 233 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -3616,7 +3616,7 @@
36163616
{
36173617
"label": "Policy",
36183618
"language": "",
3619-
"url": "https://publisher.hitachienergy.com/preview?DocumentID=9AKK107991A7713&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch"
3619+
"url": "https://publisher.hitachienergy.com/preview?DocumentID=9AKK107991A7713&LanguageCode=en&DocumentPartId=&Action=Launch"
36203620
}
36213621
],
36223622
"securityAdvisories": {
@@ -5684,16 +5684,16 @@
56845684
"country": "USA"
56855685
},
56865686
{
5687-
"shortName": "NLOK",
5687+
"shortName": "GEN",
56885688
"cnaID": "CNA-2020-0016",
5689-
"organizationName": "NortonLifeLock Inc.",
5690-
"scope": "All NortonLifeLock product issues only.",
5689+
"organizationName": "Gen Digital Inc.",
5690+
"scope": "All Gen Digital products and websites.",
56915691
"contact": [
56925692
{
56935693
"email": [
56945694
{
56955695
"label": "Email",
5696-
"emailAddr": "security@nortonlifelock.com"
5696+
"emailAddr": "security@gendigital.com"
56975697
}
56985698
],
56995699
"contact": [],
@@ -5704,15 +5704,15 @@
57045704
{
57055705
"label": "Policy",
57065706
"language": "",
5707-
"url": "https://www.nortonlifelock.com/content/dam/nortonlifelock/pdfs/other-resources/guidelines-for-security-vulnerability-reporting-and-response-en.pdf"
5707+
"url": "https://www.gendigital.com/us/en/contact-us/report-a-potential-security-vulnerability/"
57085708
}
57095709
],
57105710
"securityAdvisories": {
57115711
"alerts": [],
57125712
"advisories": [
57135713
{
57145714
"label": "Advisories",
5715-
"url": "https://us.norton.com/support/tools/security-advisories.html"
5715+
"url": "https://www.gendigital.com/us/en/contact-us/security-advisories/"
57165716
}
57175717
]
57185718
},
@@ -28640,5 +28640,231 @@
2864028640
]
2864128641
},
2864228642
"country": "USA"
28643+
},
28644+
{
28645+
"shortName": "HDFG",
28646+
"cnaID": "CNA-2026-0016",
28647+
"organizationName": "The HDF Group",
28648+
"scope": "All HDF software including HDF5, HDF4, HSDS, HDFView.",
28649+
"contact": [
28650+
{
28651+
"email": [
28652+
{
28653+
"label": "Email",
28654+
"emailAddr": "security@hdfgroup.org"
28655+
}
28656+
],
28657+
"contact": [],
28658+
"form": []
28659+
}
28660+
],
28661+
"disclosurePolicy": [
28662+
{
28663+
"label": "Policy",
28664+
"language": "",
28665+
"url": "https://github.com/HDFGroup/hdf5/blob/develop/SECURITY.md"
28666+
}
28667+
],
28668+
"securityAdvisories": {
28669+
"alerts": [],
28670+
"advisories": [
28671+
{
28672+
"label": "Advisories",
28673+
"url": "https://github.com/HDFGroup/hdf5/security/advisories"
28674+
}
28675+
]
28676+
},
28677+
"resources": [],
28678+
"CNA": {
28679+
"isRoot": false,
28680+
"root": {
28681+
"shortName": "redhat",
28682+
"organizationName": "Red Hat, Inc."
28683+
},
28684+
"type": [
28685+
"Open Source"
28686+
],
28687+
"TLR": {
28688+
"shortName": "mitre",
28689+
"organizationName": "MITRE Corporation"
28690+
},
28691+
"roles": [
28692+
{
28693+
"helpText": "",
28694+
"role": "CNA"
28695+
}
28696+
]
28697+
},
28698+
"country": "USA"
28699+
},
28700+
{
28701+
"shortName": "FB",
28702+
"cnaID": "CNA-2026-0017",
28703+
"organizationName": "Fujifilm Business Innovation Corp.",
28704+
"scope": "Fuji Xerox and FUJIFILM Business Innovation products such as multifunction devices, printers, production printers, software, and cloud services.",
28705+
"contact": [
28706+
{
28707+
"email": [
28708+
{
28709+
"label": "Email",
28710+
"emailAddr": "dgi-fb_vulnerability_report@fujifilm.com"
28711+
}
28712+
],
28713+
"contact": [],
28714+
"form": []
28715+
}
28716+
],
28717+
"disclosurePolicy": [
28718+
{
28719+
"label": "Policy",
28720+
"language": "",
28721+
"url": "https://www.fujifilm.com/fbglobal/eng/company/quality/vdp"
28722+
}
28723+
],
28724+
"securityAdvisories": {
28725+
"alerts": [],
28726+
"advisories": [
28727+
{
28728+
"label": "Advisories",
28729+
"url": "https://www.fujifilm.com/fbglobal/eng/company/quality/product_security/vulnerability"
28730+
}
28731+
]
28732+
},
28733+
"resources": [],
28734+
"CNA": {
28735+
"isRoot": false,
28736+
"root": {
28737+
"shortName": "jpcert",
28738+
"organizationName": "JPCERT/CC"
28739+
},
28740+
"roles": [
28741+
{
28742+
"helpText": "",
28743+
"role": "CNA"
28744+
}
28745+
],
28746+
"TLR": {
28747+
"shortName": "mitre",
28748+
"organizationName": "MITRE Corporation"
28749+
},
28750+
"type": [
28751+
"Vendor"
28752+
]
28753+
},
28754+
"country": "Japan"
28755+
},
28756+
{
28757+
"shortName": "Acer",
28758+
"cnaID": "CNA-2026-0018",
28759+
"organizationName": "Acer Inc.",
28760+
"scope": "Acer issues only.",
28761+
"contact": [
28762+
{
28763+
"email": [
28764+
{
28765+
"label": "Email",
28766+
"emailAddr": "vulnerability@acer.com"
28767+
}
28768+
],
28769+
"contact": [],
28770+
"form": []
28771+
}
28772+
],
28773+
"disclosurePolicy": [
28774+
{
28775+
"label": "Policy",
28776+
"language": "",
28777+
"url": "https://www.acer.com/us-en/support/security-advisory"
28778+
}
28779+
],
28780+
"securityAdvisories": {
28781+
"alerts": [],
28782+
"advisories": [
28783+
{
28784+
"label": "Advisories",
28785+
"url": "https://www.acer.com/us-en/support/security-advisory"
28786+
}
28787+
]
28788+
},
28789+
"resources": [],
28790+
"CNA": {
28791+
"isRoot": false,
28792+
"root": {
28793+
"shortName": "n/a",
28794+
"organizationName": "n/a"
28795+
},
28796+
"roles": [
28797+
{
28798+
"helpText": "",
28799+
"role": "CNA"
28800+
}
28801+
],
28802+
"TLR": {
28803+
"shortName": "mitre",
28804+
"organizationName": "MITRE Corporation"
28805+
},
28806+
"type": [
28807+
"Vendor"
28808+
]
28809+
},
28810+
"country": "Taiwan"
28811+
},
28812+
{
28813+
"shortName": "Canva",
28814+
"cnaID": "CNA-2026-0019",
28815+
"organizationName": "Canva",
28816+
"scope": "All Canva products, including open-source software published and maintained by Canva, as well as vulnerabilities in third-party software discovered by Canva that are not in another CNA’s scope.",
28817+
"contact": [
28818+
{
28819+
"email": [
28820+
{
28821+
"label": "Email",
28822+
"emailAddr": "security@canva.com"
28823+
}
28824+
],
28825+
"contact": [],
28826+
"form": []
28827+
}
28828+
],
28829+
"disclosurePolicy": [
28830+
{
28831+
"label": "Policy",
28832+
"language": "",
28833+
"url": "https://www.canva.com/security/bug-bounty/"
28834+
}
28835+
],
28836+
"securityAdvisories": {
28837+
"alerts": [],
28838+
"advisories": [
28839+
{
28840+
"label": "Advisories",
28841+
"url": "https://trust.canva.com/"
28842+
}
28843+
]
28844+
},
28845+
"resources": [],
28846+
"CNA": {
28847+
"isRoot": false,
28848+
"root": {
28849+
"shortName": "n/a",
28850+
"organizationName": "n/a"
28851+
},
28852+
"roles": [
28853+
{
28854+
"helpText": "",
28855+
"role": "CNA"
28856+
}
28857+
],
28858+
"TLR": {
28859+
"shortName": "mitre",
28860+
"organizationName": "MITRE Corporation"
28861+
},
28862+
"type": [
28863+
"Vendor",
28864+
"Open Source",
28865+
"Researcher"
28866+
]
28867+
},
28868+
"country": "Australia"
2864328869
}
2864428870
]

src/assets/data/events.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@
6363
"displayOnHomepageOrder": 1,
6464
"title": "CVE/FIRST VulnCon 2026",
6565
"location": "Scottsdale, Arizona, USA & Virtual",
66-
"description": "REGISTRATION IS OPEN!<br/>Closes April 6, 2026.<br/><br/>VulnCon is co-hosted by the <a href='/'>CVE Program</a> and <a href='https://www.first.org/conference/vulncon26/' target='_blank'>FIRST</a> and is open to the public.<br/><br/><strong>Agenda</strong>:<br/>Available on the <a href='https://www.first.org/conference/vulncon26/program' target='_blank'>conference web page</a> or view the schedule by day:<br/><br/><strong>Monday, April 13</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260413' target='_blank'>View day 1 schedule</a><br/><strong>Tuesday, April 14</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260414' target='_blank'>View day 2 schedule</a><br/><strong>Wednesday, April 15</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260415' target='_blank'>View day 3 schedule</a><br/><strong>Thursday, April 16</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260416' target='_blank'>View day 4 schedule</a><br/><br/>An Offsite Social Event will be held at the Western Spirit Museum on Wednesday, April 15. Learn more <a href='https://www.first.org/conference/vulncon26/registration#Registration-Information' target='_blank'>here</a>.<br/><br/><strong>Registration</strong>:<br/>Both virtual and in-person registration are open now on the VulnCon 2026 <a href='https://www.first.org/conference/vulncon26/registration#Registration-Information' target='_blank'>conference registration page</a> hosted on the FIRST website. <ul><li>Standard Admission (by March 14, 2026): US $525.00</li><li>Late Rate Admission (after March 14, 2026): US $600.00</li><li>Virtual Admission: US $100.00</li></ul>Registration fees include full admission to conference activities Monday through Thursday; continental breakfast, lunch, and two coffee breaks Tuesday through Thursday; entry to the Monday welcome reception; entry to the Tuesday networking reception; entry to the vendor hall; all applicable conference materials;, and access to live streams and applicable apps.<br/><br/><i>NOTE: Registration closes on April 6, 2026, at 19:00 UTC. Registration is based on availability and may close before the indicated date. Learn more <a href='https://www.first.org/conference/vulncon26/registration#Registration-Information' target='_blank'>here</a>.</i><br/><br/><strong>Purpose:</strong><br/>The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.<br/><br/>A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.<br/><br/><strong>Call for Speakers (CFS)</strong>:<br/>Closed on December 22, 2025. The <a href='https://www.first.org/conference/vulncon26/cfs' target='_blank'>CFS</a> requirements and submission process are available <a href='https://www.first.org/conference/vulncon26/cfs' target='_blank'>here</a>.",
66+
"description": "<i>Registration closes on April 6, 2026, at 19:00 UTC.</i><br/><br/>VulnCon is co-hosted by the <a href='/'>CVE Program</a> and <a href='https://www.first.org/conference/vulncon26/' target='_blank'>FIRST</a> and is open to the public.<br/><br/><strong>Agenda</strong>:<br/>Available on the <a href='https://www.first.org/conference/vulncon26/program' target='_blank'>conference web page</a> or view the schedule by day:<br/><br/><strong>Monday, April 13</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260413' target='_blank'>View day 1 schedule</a><br/><strong>Tuesday, April 14</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260414' target='_blank'>View day 2 schedule</a><br/><strong>Wednesday, April 15</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260415' target='_blank'>View day 3 schedule</a><br/><strong>Thursday, April 16</strong> &mdash; <a href='https://www.first.org/conference/vulncon26/program#d20260416' target='_blank'>View day 4 schedule</a><br/><br/>An Offsite Social Event will be held at the Western Spirit Museum on Wednesday, April 15. Learn more <a href='https://www.first.org/conference/vulncon26/registration#Registration-Information' target='_blank'>here</a>.<br/><br/><strong>Registration</strong>:<br/>Both virtual and in-person registration are open now on the VulnCon 2026 <a href='https://www.first.org/conference/vulncon26/registration#Registration-Information' target='_blank'>conference registration page</a> hosted on the FIRST website. <ul><li>Standard Admission (by March 14, 2026): US $525.00</li><li>Late Rate Admission (after March 14, 2026): US $600.00</li><li>Virtual Admission: US $100.00</li></ul>Registration fees include full admission to conference activities Monday through Thursday; continental breakfast, lunch, and two coffee breaks Tuesday through Thursday; entry to the Monday welcome reception; entry to the Tuesday networking reception; entry to the vendor hall; all applicable conference materials;, and access to live streams and applicable apps.<br/><br/><i>NOTE: Registration closes on April 6, 2026, at 19:00 UTC. Registration is based on availability and may close before the indicated date. Learn more <a href='https://www.first.org/conference/vulncon26/registration#Registration-Information' target='_blank'>here</a>.</i><br/><br/><strong>Purpose:</strong><br/>The purpose of VulnCon is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem.<br/><br/>A key goal of the conference is to understand what important stakeholders and programs are doing within the vulnerability management ecosystem and best determine how to benefit the ecosystem broadly.<br/><br/><strong>Call for Speakers (CFS)</strong>:<br/>Closed on December 22, 2025. The <a href='https://www.first.org/conference/vulncon26/cfs' target='_blank'>CFS</a> requirements and submission process are available <a href='https://www.first.org/conference/vulncon26/cfs' target='_blank'>here</a>.",
6767
"permission": "public",
6868
"url": "https://www.first.org/conference/vulncon26/",
6969
"date": {

src/assets/data/metrics.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1180,7 +1180,7 @@
11801180
},
11811181
{
11821182
"month": "March",
1183-
"value": "4"
1183+
"value": "8"
11841184
},
11851185
{
11861186
"month": "April",

0 commit comments

Comments
 (0)