Cohesity · Vulnerability Disclosure

Cohesity Vulnerability Disclosure

Vulnerability disclosure

Cohesity runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AutomationBackupCyber ResilienceData ManagementData ProtectionData SecurityDataProtectDisaster RecoveryHeliosOrchestrationRansomware RecoverySite ContinuityReportingModel Context ProtocolEnterprise Storage
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://www.cohesity.com/forms/contact/security/

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-05'
method: searched
probe: true
policy:
  - https://www.cohesity.com/trust/security-profile/
contact:
  - https://www.cohesity.com/forms/contact/security/
bug_bounty: null
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti program was found for Cohesity. Reports are
  taken through a first-party contact form, not a bounty platform.
security_txt: false
security_txt_note: >-
  /.well-known/security.txt was probed on cohesity.com, www.cohesity.com,
  developer.cohesity.com, developers.cohesity.com, docs.cohesity.com,
  api.cohesity.com and helios.cohesity.com. Every host returned 404 or an SPA
  shell - Cohesity publishes no RFC 9116 document. This is the cheapest fix
  available to them: the disclosure program already exists, it is just not
  machine-discoverable.
advisories:
  url: https://github.com/cohesity/SecAdvisory
  format: One markdown file per advisory in a public GitHub repository.
  identifiers: [CVE, 'COH-YYYY-NNNN']
  examples: [COH-2026-0001, COH-2026-0002, CVE-2023-33295, CVE-2021-36795, CVE-2021-28123, CVE-2021-28124]
  last_updated: '2026-08-28'
statement: >-
  "Customers, partners, and third-party researchers may report vulnerabilities in
  Cohesity products and services by contacting Cohesity Security."
evidence:
  - {source: 'https://www.cohesity.com/trust/security-profile/', kind: disclosure-policy, http_status: 200}
  - {source: 'https://www.cohesity.com/forms/contact/security/', kind: security-contact, http_status: 200}
  - {source: 'https://github.com/cohesity/SecAdvisory', kind: advisory-registry, http_status: 200}
  - {source: 'https://www.cohesity.com/.well-known/security.txt', kind: security.txt, http_status: 404}
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cohesity-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.