Fannie Mae · Vulnerability Disclosure
Fannie Mae Vulnerability Disclosure
Vulnerability disclosure
Fannie Mae runs a coordinated vulnerability disclosure program on Hackerone.
Federal-GovernmentHousingMortgagesFinanceGSEFortune 100
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-07'
method: searched
source: https://www.fanniemae.com/about-us/reporting-technology-vulnerability
note: >-
Fannie Mae runs a first-party vulnerability disclosure channel — a published policy page and an
intake form on its own domain. It does NOT run a bug bounty. The hackerone.com/fanniemae page that
turns up in search is HackerOne's community-curated, explicitly UNCLAIMED directory entry (the page
carries class "spec-external-unclaimed" and describes itself as "community-curated"); it is
recorded here as a third-party listing, not as a Fannie Mae program.
program:
exists: true
type: vulnerability-disclosure-policy
bug_bounty: false
first_party: true
policy_url: https://www.fanniemae.com/about-us/reporting-technology-vulnerability
policy_status: 200
submission_form: https://www.fanniemae.com/form/report-technology-vulnerability
submission_form_status: 200
security_txt: null
security_txt_note: >-
/.well-known/security.txt returns 404 on www.fanniemae.com, fanniemae.com and
fmsso.fanniemae.com. The disclosure channel exists but is not machine-discoverable — publishing
an RFC 9116 security.txt pointing at the existing form would close this with no new process.
contact_email: iso_support@fanniemae.com
contact_email_source: >-
CAA iodef record on fanniemae.com — 128 iodef "mailto: iso_support@fanniemae.com" (see
security/fannie-mae-domain-security.yml). This is the incident contact Fannie Mae publishes in DNS.
submission_requirements:
- Name, organization and contact information
- Description of the vulnerability
- Technical details
stated_terms:
- Reporters are instructed not to include nonpublic personal information (SSNs, financial account numbers) in a report.
- Fannie Mae may share a report with law enforcement agencies or other industry participants.
- Fannie Mae states it may not respond to the reporter or keep them apprised of the report's validity.
- Vulnerabilities involving potential bodily harm should be reported to law enforcement immediately.
safe_harbor: false
safe_harbor_note: The policy page carries no explicit safe-harbor or researcher legal-protection language.
third_party_listings:
- platform: HackerOne
url: https://hackerone.com/fanniemae
status: 200
claimed_by_provider: false
kind: community-curated directory entry
related:
cybersecurity_requirements: https://www.fanniemae.com/about-us/corp-responsibility/governance/information-security-and-business-resiliency-supplement
cybersecurity_requirements_status: 200
cybersecurity_requirements_note: >-
Requirements Fannie Mae imposes on its sellers, servicers and technology partners (including a
36-hour cybersecurity incident notification obligation) — an obligation Fannie Mae places on
others, not a certification Fannie Mae holds. It is deliberately NOT recorded as a trust center
or compliance attestation.
trust_center:
exists: false
note: >-
No trust center, no published SOC 2 / ISO 27001 / PCI / FedRAMP attestation, and no compliance
portal was found on any fanniemae.com host (probe-security-programs.py 2026-09-07 returned
vdp=none trust=none; this file is the manual upgrade of its vdp result). Fannie Mae is a
government-sponsored enterprise supervised by FHFA; its published governance material is
regulatory, not a customer-facing certification set.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/fannie-mae-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.