Marketo · Vulnerability Disclosure

Marketo Vulnerability Disclosure

Vulnerability disclosure

Marketo runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AdobeAutomationMarketingMarketing AutomationEmail MarketingLead ManagementCampaign ManagementCRMCustomer EngagementB2B
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://hackerone.com/adobe
Contact
psirt@adobe.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: probed
probe: true
source: https://www.adobe.com/.well-known/security.txt
ownership_note: >-
  Marketo Engage is an Adobe product. www.marketo.com 301s to
  business.adobe.com/products/marketo/adobe-marketo.html and there is no
  marketo.com-hosted disclosure surface, so the governing vulnerability
  disclosure program is Adobe PSIRT's. Recorded here because it is the program
  that receives a Marketo Engage report, not because it is Marketo-specific.
policy:
  - https://helpx.adobe.com/security.html/security/policy.ug.html
contact:
  - https://hackerone.com/adobe
  - psirt@adobe.com
bug_bounty:
  platform: HackerOne
  url: https://hackerone.com/adobe
  program: Adobe
encryption_key: https://helpx.adobe.com/security/key.html
acknowledgments: https://helpx.adobe.com/security.html
preferred_languages: [en, ro, hi]
expires: '2027-07-30T01:00:00.000Z'
canonical: https://www.adobe.com/.well-known/security.txt
signed: true
signature: PGP SIGNED MESSAGE, SHA256, Adobe PSIRT <PSIRT@adobe.com>
rfc9116_conformant: true
evidence:
  - source: https://www.adobe.com/.well-known/security.txt
    kind: security.txt
    http_status: 200
    content_type: text/plain; charset=UTF-8
    bytes: 3600
    fetched: '2026-08-13'
  - source: well-known/marketo-security.txt
    kind: security.txt
    note: Verbatim copy saved by this pass.
probe_limitations: >-
  helpx.adobe.com and business.adobe.com refused every request from this run
  (curl exit 000 — connection reset before response, across three user agents and
  both HTTP/1.1 and HTTP/2). The Policy and Acknowledgments URLs above are
  therefore recorded as PUBLISHED BY Adobe in its signed security.txt, not as
  independently fetched pages.