Administer

Security advisories

Open
0
Mitigated
1
Patched
1

Triage owner

Owner
Varga Zoltán
Site security lead
Site security lead
If unavailable
Backup: ARIS support PSIRT desk (psirt@smartrack-vendor.example), 4 h SLA.

Response SLA by severity

Low168 h
Medium72 h
High24 h
Critical4 h
Details
ADV-2026-003 HighGateway Agent journal replay could accept unsigned entries after restore30 May 2026 Patched Not yet acknowledged
ADV-2026-007 MediumIntegration Runner file connector follows symlinks outside the allowlisted drop folder10 Jul 2026 Mitigated Not yet acknowledged
  • Severity
    High
    Title
    Gateway Agent journal replay could accept unsigned entries after restore
    Status
    Patched
  • Severity
    Medium
    Title
    Integration Runner file connector follows symlinks outside the allowlisted drop folder
    Status
    Mitigated

Tabletop exercises

18 Feb 2026Simulated critical remote-code-execution advisory against the gateway agentVarga Zoltán, Bencze Ádám (ARIS support)Completed — all follow-up action items closed

Emergency release procedure

1. Triage owner confirms severity and scope within the response SLA
2. Fix is built and signed with the vendor release key, offline from the affected site
3. If the exposure involves key compromise, the affected key is revoked before the fix ships
4. Advisory and capsule are published to the offline mirror bundled with the next update

PSIRT contact

Email
psirt@smartrack-vendor.example — PGP key published on the vendor advisory page; 4 h acknowledgement SLA
Advisory portal
advisories.smartrack-vendor.example (offline mirror shipped with each capsule) — Air-gapped sites use the offline mirror bundled in the update capsule