Australian-developed encryption for government, critical infrastructure and enterprise Australian-developed · Sydney Confidential briefings available

Security advisories

The authoritative public register for QES security notices.

QES uses this page to publish customer-relevant security advisories, affected scope, recommended action and release guidance when public notification is appropriate.

Public advisory register

Last reviewed: August 2026

Register current

No public advisories are currently listed.

This status means there is no customer-facing security notice published in this register at the time shown. It is not a substitute for the release-specific guidance provided directly to customers.

Report a security concern

What an advisory will contain

Actionable information without unnecessary exposure.

Where publication is required, QES advisories are structured to help customers determine whether they are affected and what they should do next.

Identification

Advisory reference

A unique notice identifier, publication date and update history.

Scope

Affected products

Supported releases, operating surfaces and conditions relevant to the issue.

Action

Customer guidance

Required update, configuration, operational mitigation or other recommended response.

Resolution

Fixed status

Corrected release information and any follow-up steps for customers.

Notification

Customer communication is matched to consequence.

QES may use direct customer channels in addition to this public register where a matter requires prompt or deployment-specific action. Public detail may be limited where broader publication would increase exploitation risk.

Organisations requiring defined security-notification arrangements should address those requirements during contracting and deployment planning.

Discuss notification requirements
Public registerAuthoritative notices suitable for broad publication
This page
Customer notificationDeployment-relevant guidance through agreed channels
Contract-based
Security reportingResponsible disclosure intake and triage
Available
Remediation guidanceAction aligned to affected scope and supported releases
Issue-based

Found a potential issue?

Do not wait for an advisory to report it.

Use the QES vulnerability disclosure process and send the minimum information required for safe investigation.

Encrypt everything.