Advisory reference
A unique notice identifier, publication date and update history.
Security advisories
QES uses this page to publish customer-relevant security advisories, affected scope, recommended action and release guidance when public notification is appropriate.
Last reviewed: August 2026
This status means there is no customer-facing security notice published in this register at the time shown. It is not a substitute for the release-specific guidance provided directly to customers.
Report a security concernWhat an advisory will contain
Where publication is required, QES advisories are structured to help customers determine whether they are affected and what they should do next.
A unique notice identifier, publication date and update history.
Supported releases, operating surfaces and conditions relevant to the issue.
Required update, configuration, operational mitigation or other recommended response.
Corrected release information and any follow-up steps for customers.
Notification
QES may use direct customer channels in addition to this public register where a matter requires prompt or deployment-specific action. Public detail may be limited where broader publication would increase exploitation risk.
Organisations requiring defined security-notification arrangements should address those requirements during contracting and deployment planning.
Discuss notification requirementsFound a potential issue?
Use the QES vulnerability disclosure process and send the minimum information required for safe investigation.
Encrypt everything.