Xylem · Vulnerability Disclosure
Xylem Vulnerability Disclosure
Vulnerability disclosure
Xylem runs a coordinated vulnerability disclosure program on Hackerone.
Fortune 1000WaterWater TechnologyUtilitiesSmart MeteringIndustrial IoTWater QualityWastewaterManufacturing
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-04'
method: searched
source: https://www.xylem.com/en-us/about/cybersecurity/incident-response/
note: >-
probe-security-programs.py reported vdp=none because Xylem serves no
/.well-known/security.txt on any host — the one security.txt reachable under a Xylem
hostname belongs to Atlassian Statuspage, not to Xylem (see
well-known/xylem-well-known.yml). The programme is nonetheless real and first-party;
it is published as prose under www.xylem.com/en-us/about/cybersecurity/ and was
read there on 2026-09-04. This artifact is hand-written from those pages.
program: Xylem Product Security Incident Response Team (PSIRT)
policy_type: Coordinated Vulnerability Disclosure (CVD)
policy_url: https://www.xylem.com/en-us/about/cybersecurity/incident-response/
contact_url: https://www.xylem.com/en-us/about/cybersecurity/contact/
advisories_url: https://www.xylem.com/en-us/about/cybersecurity/security-advisories/
contacts:
- method: email
value: security@xylem.com
note: Primary reporting address named on the cybersecurity contact page.
- method: email
value: product.security@xylem.com
note: Alternate address for security researchers, customers, vendors and industry partners.
encryption:
supported: true
method: PGP
note: >-
Xylem asks that confidential report content be PGP-encrypted and offers a downloadable
Xylem PSIRT public key from the cybersecurity contact page.
cna:
is_cve_numbering_authority: true
scope: Xylem products and technologies
evidence: >-
https://www.xylem.com/en-us/about/cybersecurity/incident-response/ — "Xylem is also
an approved CVE Numbering Authority (CNA) for its products and technologies."
bug_bounty:
offered: false
note: No bug bounty, safe-harbour statement, or HackerOne/Bugcrowd/Intigriti programme found.
reporting_requirements:
- Product name and version
- Description of the potential vulnerability
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce
- Proof of concept or exploit code, if available
- Potential impact
process:
- step: 1
name: Acknowledge and triage
detail: Xylem PSIRT acknowledges the report and begins triage.
- step: 2
name: Risk assessment
detail: >-
Valid reports get a risk assessment based on technical severity, business impact
and product.
- step: 3
name: Remediation plan
detail: >-
Patches, updates, configuration changes, or compensating controls, chosen against
the assessed risk.
- step: 4
name: Coordinated disclosure
detail: >-
PSIRT coordinates disclosure through customer notifications, security advisories,
or DHS CISA as appropriate.
regulatory_alignment:
- EU Cyber Resilience Act (stated alignment for intake, triage, remediation and disclosure)
advisories:
format: Numbered advisories, XPSA-<year>-<seq> (product) and XSA-<year>-<seq> (company/threat)
count_published: 17
oldest: '2019-08-14'
newest: '2024-11-20'
feed: null
feed_note: >-
No RSS or Atom feed for advisories was found; subscription is via a marketing
newsletter sign-up form on the same pages.
sample:
- id: XPSA-2024-015
date: '2024-11-20'
title: Disclosure of Sensus wM-Bus Default Encryption Key
- id: XPSA-2024-001
date: '2024-07-09'
title: CVE-2024-6387 OpenSSH
cve: CVE-2024-6387
- id: XPSA-2023-014
date: '2023-11-16'
title: CVE-2023-46604 for Sensus RNI
cve: CVE-2023-46604
- id: XPSA-2022-009
date: '2022-05-25'
title: Sensus Analytics Login Service Vulnerability
- id: XPSA-2021-004
date: '2021-12-16'
title: AquaView Hardcoded Credentials Vulnerability
memberships:
- WaterISAC (Water Information Sharing and Analysis Center)
- ISA Global Cybersecurity Alliance (ISAGCA)
gaps:
- >-
No /.well-known/security.txt on xylem.com, www.xylem.com or any product host, so the
programme is invisible to a machine even though it is well documented for a human.
Publishing an RFC 9116 file naming security@xylem.com, the CVD policy URL and the
PSIRT PGP key would make it discoverable at zero cost.
- No machine-readable advisory feed (RSS/Atom/CSAF/VEX) alongside the advisory list.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/xylem-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.