← Sectigo cases
Bugzilla #1972158 Incident Audit Finding

Sectigo: Lack of documentation for vulnerability NVD rating adjustment

RESOLVED FIXED Sectigo
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Sectigo disclosed an incident related to vulnerability management documentation discovered during its annual WebTrust audit. The CA reported that for two vulnerabilities requested as samples during the audit, it became aware that no proper internal documentation existed for the decision-making process leading to an adjustment of each vulnerability’s NVD rating. The incident was identified after WebTrust audit evidence requests and reminders, and Sectigo stated that it declared the matter an incident when it did not have further evidence available. Sectigo also reported that, while the vulnerabilities had already been patched, it recast the vulnerabilities in its scanning software with proper comments around the reasoning for the recast. In its remediation, Sectigo increased headcount responsible for vulnerability scanning and instigated a weekly, multi-person standing call for vulnerability scanning review. Sectigo provided a report closure summary stating that the disclosed action items were completed and requested closure, and the bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:56 UTC Revised: 2026-06-16 19:04 UTC Confidence: 0.86 5 comments
Chronology
  1. Vulnerability #1 was first discovered.
  2. Vulnerability #2 was officially registered as mitigated.
  3. Sectigo identified the lack of evidence and declared the matter an incident after receiving draft WebTrust audit reports.
  4. Sectigo recast the vulnerabilities in its scanning software with comments explaining the NVD rating recast reasoning.
  5. Sectigo posted the report closure summary and requested closure after completing action items.
Thread Activity
  1. Sectigo — Martijn Katerbarg opened a preliminary incident report stating that no proper internal documentation existed for the decision process behind adjusting the vulnerabilities’ NVD ratings, discovered via the annual WebTrust audit.
  2. Sectigo — Martijn Katerbarg posted a full incident report with a timeline, root cause (single person responsibility), and remediation details.
  3. Sectigo — Martijn Katerbarg indicated they would post a report closure summary unless questions were raised.
  4. Sectigo — Martijn Katerbarg posted the report closure summary, stating action items were completed and requesting closure.
  5. CCADB representative — CCADB incident reporting requested final comments and stated the incident would be closed approximately 2025-07-15 if no questions were posted.
Participants
Sectigo CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1972547 RESOLVED Incident Policy Document Issue Opened 2025-06-17 · Closed 2025-07-16 · 99% similar
Sectigo: Lack of technical controls for multiparty control access to Secure Zone
#2000277 RESOLVED Incident Opened 2025-11-14 · Closed 2025-12-19 · 98% similar
Sectigo: Certificate issuance by non-compliant Extant S/MIME CA
#1954580 RESOLVED Incident Revocation Issue Opened 2025-03-17 · Closed 2025-05-16 · 96% similar
Sectigo: Temporary failure to publish OCSP responses for newly issued certificates
#1985307 RESOLVED Incident Opened 2025-08-26 · Closed 2025-10-09 · 96% similar
Sectigo: OCSP and CRL traffic not being proxied for 3 Subordinate CAs
#1991196 RESOLVED Incident Opened 2025-09-26 · Closed 2025-12-01 · 96% similar
Sectigo: OCSP, caIssuers, and CRL endpoints unavailable for a single Subordinate CA
#1869056 RESOLVED Incident Opened 2023-12-08 · Closed 2024-02-02 · 91% similar
Sectigo: Inadequate vulnerability scanning and patching
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 90% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1876775 RESOLVED Incident Opened 2024-01-26 · Closed 2024-03-04 · 88% similar
Sectigo: Wrong usage of LEI records for the issuance of SMIME Certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action