Sectigo: Package patching gap within Certificate Systems
Sectigo reported a compliance incident discovered through its internal audit process: a gap in package patching within its Certificate Systems. The incident involved an operating system package with Critical severity that was not upgraded across multiple servers, including three K3S servers, within the required timeframe. Sectigo stated that it opened and tracked patching tickets in June 2025, with the Critical severity patch expected by 2025-06-13 but completed later. Sectigo completed patching of the affected CA Systems on 2026-02-27 and provided a root cause analysis citing insufficiently defined ownership/accountability, insufficient reinforcement of existing processes, and lack of effective verification controls. For remediation, Sectigo refined process documentation, implemented monitoring with automated notifications for critical patching tickets, and completed additional staff training, and it also planned to review and update patching practices and policies. The report closure summary states that all disclosed action items were completed as described and requests closure, with a final call for comments indicating closure on approximately 2026-04-08. The bug is resolved as FIXED.
- Critical-severity package patching was due for Certificate Systems but was not completed by the required time.
- Sectigo’s internal audit identified the patching failure for Certificate Systems.
- Sectigo completed patching of the affected CA Systems.
- Sectigo reported remediation completion and requested closure of the incident report.
- Sectigo — Opened a preliminary incident report stating an internal audit found a gap in package patching and that at least one package across Kubernetes hosts was not patched/remediated within the required timeframe.
- Sectigo — Submitted a full incident report with a timeline, stating a Critical-severity OS package was not upgraded across multiple servers and providing root cause analysis.
- Sectigo — Requested a next update for 2026-04-10 while working on action items.
- Sectigo — Reported action items as completed, described remediation steps (process documentation, monitoring/automated notifications, and staff training), and requested closure.
- CCADB representative — Issued a final call for comments and noted the incident report would be closed on approximately 2026-04-08.