AbbVie · Vulnerability Disclosure

Abbvie Vulnerability Disclosure

Vulnerability disclosure

AbbVie runs a coordinated vulnerability disclosure program on Hackerone.

PharmaceuticalsbiopharmaceuticalsHealthcareLife SciencesDrug DiscoveryFortune 500
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

abbvie-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-29'
method: searched
probe: true
source: https://cvd.abbvie.com/
note: >-
  AbbVie runs a Coordinated Vulnerability Disclosure (CVD) process on its own host at
  cvd.abbvie.com, scoped to Medical Devices and Software as a Medical Device — not to a
  web/API bug bounty. Submissions go through a web form; AbbVie commits to acknowledging
  receipt within 5 business days, evaluating and attempting to reproduce the report, and
  publishing a notification on the CVD page when it determines disclosure is warranted.
  No security.txt is served (cvd.abbvie.com answers /.well-known/security.txt with the same
  55,923-byte SPA shell as /), and hackerone.com/abbvie returns 404 — there is no bug bounty.
policy:
  - https://cvd.abbvie.com/
submission_form: https://cvd.abbvie.com/vulnerability-submission
contact: []
bug_bounty: false
security_txt: false
scope:
  - Medical Devices
  - Software as a Medical Device
out_of_scope:
  - Technical support for AbbVie products
  - Adverse Events and Product Quality Complaints (call 844-663-3742 / abbviemedinfo.com)
response_commitments:
  acknowledgement: 5 business days
  disclosure: Published on cvd.abbvie.com when AbbVie determines disclosure is warranted
evidence:
  - source: https://cvd.abbvie.com/
    kind: disclosure-page
    http_status: 200
    fetched: '2026-08-29'
  - source: https://cvd.abbvie.com/vulnerability-submission
    kind: submission-form
    http_status: 200
    fetched: '2026-08-29'
  - source: https://hackerone.com/abbvie
    kind: bug-bounty-probe
    http_status: 404
    fetched: '2026-08-29'
  - source: https://cvd.abbvie.com/.well-known/security.txt
    kind: security-txt-probe
    http_status: 200
    soft_404: true
    fetched: '2026-08-29'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/abbvie-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.