This website uses cookies to ensure you get the best experience on our website. By continuing to browse the site, you agree to our use of cookies.

More info ››
Contact sales: 1-888-DISK-IMAGE

1-888-DISK-IMAGE (1-888-347-5462)

Sales North America

+49-761-59018-202

Sales Europe

+81(3)3265-1278

Sales Japan

+7 (495) 789-6717

Sales Russia

Contact sales: 1-888-DISK-IMAGE

1-888-DISK-IMAGE (1-888-347-5462)

Sales North America

+49-761-59018-202

Sales Europe

+81(3)3265-1278

Sales Japan

+7 (495) 789-6717

Sales Russia

Report Active Exploitation or a Severe Incident

Active since 11 September 2026 — Article 14, Regulation (EU) 2024/2847

Scope

This channel exists for one reason: so Paragon can meet its Article 14 reporting duty. It is not our full vulnerability disclosure programme.

Report here if

  • You have evidence a Paragon product is being actively exploited — not just theoretically vulnerable
  • You’re aware of a severe incident affecting Paragon’s products or infrastructure

What happens next

  • We assess against the CRA definition of “actively exploited vulnerability” (Art. 3(42))
  • If it qualifies: early warning within 24h, full notification within 72h, final report within 14 days
  • Notifications go to our corresponding national CSIRT and ENISA (Art. 14)
  • Corresponding national CSIRT: CERT-Bund (Germany), determined under Art. 14(7)

This channel is scoped to Article 14: active exploitation and severe incidents. It is not a general bug-bounty or feature-request intake.
Source: Art. 3(42), Art. 14, Art. 14(7), Art. 71(2), Regulation (EU) 2024/2847.

Report a Case

Opens our external reporting form.

Email

Spelling error report

The following text will be sent to our editors: