Xylem · Vulnerability Disclosure

Xylem Vulnerability Disclosure

Vulnerability disclosure

Xylem runs a coordinated vulnerability disclosure program on Hackerone.

Fortune 1000WaterWater TechnologyUtilitiesSmart MeteringIndustrial IoTWater QualityWastewaterManufacturing
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

xylem-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-04'
method: searched
source: https://www.xylem.com/en-us/about/cybersecurity/incident-response/
note: >-
  probe-security-programs.py reported vdp=none because Xylem serves no
  /.well-known/security.txt on any host — the one security.txt reachable under a Xylem
  hostname belongs to Atlassian Statuspage, not to Xylem (see
  well-known/xylem-well-known.yml). The programme is nonetheless real and first-party;
  it is published as prose under www.xylem.com/en-us/about/cybersecurity/ and was
  read there on 2026-09-04. This artifact is hand-written from those pages.
program: Xylem Product Security Incident Response Team (PSIRT)
policy_type: Coordinated Vulnerability Disclosure (CVD)
policy_url: https://www.xylem.com/en-us/about/cybersecurity/incident-response/
contact_url: https://www.xylem.com/en-us/about/cybersecurity/contact/
advisories_url: https://www.xylem.com/en-us/about/cybersecurity/security-advisories/
contacts:
  - method: email
    value: security@xylem.com
    note: Primary reporting address named on the cybersecurity contact page.
  - method: email
    value: product.security@xylem.com
    note: Alternate address for security researchers, customers, vendors and industry partners.
encryption:
  supported: true
  method: PGP
  note: >-
    Xylem asks that confidential report content be PGP-encrypted and offers a downloadable
    Xylem PSIRT public key from the cybersecurity contact page.
cna:
  is_cve_numbering_authority: true
  scope: Xylem products and technologies
  evidence: >-
    https://www.xylem.com/en-us/about/cybersecurity/incident-response/ — "Xylem is also
    an approved CVE Numbering Authority (CNA) for its products and technologies."
bug_bounty:
  offered: false
  note: No bug bounty, safe-harbour statement, or HackerOne/Bugcrowd/Intigriti programme found.
reporting_requirements:
  - Product name and version
  - Description of the potential vulnerability
  - Any special configuration required to reproduce the issue
  - Step-by-step instructions to reproduce
  - Proof of concept or exploit code, if available
  - Potential impact
process:
  - step: 1
    name: Acknowledge and triage
    detail: Xylem PSIRT acknowledges the report and begins triage.
  - step: 2
    name: Risk assessment
    detail: >-
      Valid reports get a risk assessment based on technical severity, business impact
      and product.
  - step: 3
    name: Remediation plan
    detail: >-
      Patches, updates, configuration changes, or compensating controls, chosen against
      the assessed risk.
  - step: 4
    name: Coordinated disclosure
    detail: >-
      PSIRT coordinates disclosure through customer notifications, security advisories,
      or DHS CISA as appropriate.
regulatory_alignment:
  - EU Cyber Resilience Act (stated alignment for intake, triage, remediation and disclosure)
advisories:
  format: Numbered advisories, XPSA-<year>-<seq> (product) and XSA-<year>-<seq> (company/threat)
  count_published: 17
  oldest: '2019-08-14'
  newest: '2024-11-20'
  feed: null
  feed_note: >-
    No RSS or Atom feed for advisories was found; subscription is via a marketing
    newsletter sign-up form on the same pages.
  sample:
    - id: XPSA-2024-015
      date: '2024-11-20'
      title: Disclosure of Sensus wM-Bus Default Encryption Key
    - id: XPSA-2024-001
      date: '2024-07-09'
      title: CVE-2024-6387 OpenSSH
      cve: CVE-2024-6387
    - id: XPSA-2023-014
      date: '2023-11-16'
      title: CVE-2023-46604 for Sensus RNI
      cve: CVE-2023-46604
    - id: XPSA-2022-009
      date: '2022-05-25'
      title: Sensus Analytics Login Service Vulnerability
    - id: XPSA-2021-004
      date: '2021-12-16'
      title: AquaView Hardcoded Credentials Vulnerability
memberships:
  - WaterISAC (Water Information Sharing and Analysis Center)
  - ISA Global Cybersecurity Alliance (ISAGCA)
gaps:
  - >-
    No /.well-known/security.txt on xylem.com, www.xylem.com or any product host, so the
    programme is invisible to a machine even though it is well documented for a human.
    Publishing an RFC 9116 file naming security@xylem.com, the CVD policy URL and the
    PSIRT PGP key would make it discoverable at zero cost.
  - No machine-readable advisory feed (RSS/Atom/CSAF/VEX) alongside the advisory list.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/xylem-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.