← Sectigo cases
Bugzilla #1869056 Incident

Sectigo: Inadequate vulnerability scanning and patching

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo reported a self-discovered incident affecting its internal vulnerability scanning and patching. During an ETSI audit, Sectigo became aware that internal agent-based scans were not running properly and that more than 400 previously discovered vulnerabilities (418 with CVSS 7.0 or higher and marked exploitable) had not been acted upon between May 15, 2023 and the end of October 2023. Sectigo stated that internal vulnerability scans were not executed for about five months, while external weekly vulnerability scans on its CA infrastructure were not impacted. Sectigo re-enabled agent-based vulnerability scanning on November 4, 2023, developed a mitigation and remediation plan with dates for patching across datacenters, and applied patches during scheduled maintenance windows. Sectigo reported that patching was completed for DC2, that remaining DC3 vulnerabilities were mitigated through compensating controls (DC3 not directly interacting with certificate systems), and that the remaining six DC1 vulnerabilities were marked as false positives after further patching. The bug was marked RESOLVED with resolution FIXED, and Sectigo reported that two pending action items were completed by January 31, 2024; Mozilla indicated it would close the bug on or about February 2, 2024.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 18:58 UTC Confidence: 0.86 7 comments
Chronology
  1. Agent-based internal vulnerability scanning stopped working without being detected by the IT Security team.
  2. During an ETSI audit call, Sectigo presented evidence of unresolved high-severity vulnerabilities and discovered the scanning breakdown began on May 15.
  3. Sectigo re-enabled and confirmed internal agent-based vulnerability scanning was working.
  4. Sectigo reported a Tenable scan showing 0 critical vulnerabilities.
  5. Sectigo reported completion of the two remaining action items.
Thread Activity
  1. Sectigo — Sectigo opened an incident report describing deficiencies in internal vulnerability scanning and patching, including impact, timeline, and remediation actions, and set the bug resolution to FIXED.
  2. Community commenter — A commenter asked whether Tenable had delegated third-party access, and questioned how servers went about five months without updates.
  3. Sectigo — Sectigo replied that Tenable was self-hosted with access restricted to Sectigo IT/Security, explained the update/patching oversight, and stated they were implementing automated monitoring of Tenable itself.
  4. Community commenter — The commenter stated they had no further questions.
  5. Sectigo — Sectigo said it updated internal processes to remove machines properly from Tenable and requested a next update for January 31 due to pending action items.
  6. Sectigo — Sectigo reported both action items were completed on time and asked if there were further questions.
  7. Mozilla representative — Mozilla stated it would close the bug on or about Friday, 2-Feb-2024.
Participants
Sectigo Community commenter Mozilla representative
Similar Local Cases
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 99% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates
#1878139 RESOLVED Incident Opened 2024-02-01 · Closed 2024-05-20 · 98% similar
Sectigo: Failure to invalidate Email DCV Random Values after 30 days
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 97% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1741777 RESOLVED Incident Opened 2021-11-18 · Closed 2023-02-22 · 95% similar
Sectigo: OCSP responses directly signed using root certificates without KU=digitalSignature
#1891039 RESOLVED Incident Opened 2024-04-11 · Closed 2024-05-05 · 95% similar
Sectigo: Premature disabling of CRL generation for an inactive CA
#1763203 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2022-04-05 · Closed 2023-02-22 · 94% similar
Sectigo: Incorrect OCSP responses
#1830088 RESOLVED Incident Opened 2023-04-26 · Closed 2024-03-27 · 94% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1972158 RESOLVED Incident Audit Finding Opened 2025-06-14 · Closed 2025-07-16 · 91% similar
Sectigo: Lack of documentation for vulnerability NVD rating adjustment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action