Security advisories
We publish an advisory for every security vulnerability we fix in a supported product, at the point the update becomes available. Each advisory names the affected versions and the action you need to take.
Get told about new advisories
Two ways: join the email list, or subscribe to our Atom feed. The feed needs no sign-up and gives us none of your details.
| Advisory | Dates | Affected product | Severity | Identifiers | Status |
|---|---|---|---|---|---|
| GDS-2026-0001 | Updated11 Sep 2026Released21 Aug 2026Scope extended to GDSBES, which reaches the same component through the shared licence library in GDSFramework and ships version 9.0.9. GDSBES was not named when this advisory was first published. The assessment is unchanged: the affected code is not reached.2 revisions | GDSLAB, GDSBES | Critical | CVE-2026-33116CVE-2026-26171CVE-2026-32203CVE-2026-47302CVE-2026-47304CVE-2026-50648CVE-2026-50525CVE-2026-50527 | Not affected |
How to read an advisory
- Advisory ID
- Our own reference, in the form
GDS-YYYY-NNNN. Quote it when contacting support about the issue. - Dates
- Released is when we first published. Updated is the most recent revision, with a note of what changed. Check the updated date even on an advisory you have already read — we revise them as we learn more, most often to add affected serial or lot numbers, to confirm a version is unaffected, or to add a workaround.
- Severity
- CVSS v4.0 base score, banded as Critical, High, Medium or Low.
- Identifiers
- The CVE identifier where the issue has one. CVE requested means we have asked for one and it has not arrived yet — we add it as a revision when it does, so it is worth checking back. No CVE means there will not be one, and the advisory says why. Where an advisory also carries a reference such as
ICSA-…orVU#…, we coordinated the disclosure with that body and they have published their own advisory independently of ours. - Status
-
- Fixed an update is available.
- Mitigation available a workaround exists while a fix is prepared.
- Under investigation we have confirmed the report and are working on it.
- Not affected a component we ship carries the vulnerability but our product cannot reach it — the advisory explains why.
Coordinating bodies
Where an issue affects the wider industrial or scientific instrumentation community, we coordinate publication with the relevant body rather than publishing in isolation:
- CISA advisories — its ICS advisories (
ICSA-…) are the reference catalogue for industrial and control system vulnerabilities - CERT/CC Vulnerability Notes —
VU#…, a common route for multi-vendor issues - JVN — the Japanese national catalogue (
JVNVU#…) - CVE Program — the underlying identifier registry
From 11 September 2026 we are additionally required to report actively exploited vulnerabilities and severe incidents to ENISA and our national CSIRT under Article 14 of the Cyber Resilience Act. Those are regulatory notifications rather than public catalogues, so they produce no citable identifier here — see our CRA statement.
The advisory email list
We are building an email list so that anyone running our equipment is told when something needs updating — no support contract needed, and you will not need to be a customer.
It is not open yet. Rather than take addresses we cannot yet send to, the form has been taken down until the service behind it is running.
Until then, subscribe to the advisory feed. It is an Atom feed, it carries every advisory the moment it is published, and any feed reader will take it. If you would rather be told by email, write to security@gdsinstruments.com and we will add you by hand when the list opens.
Leaving
Every advisory email we send has an unsubscribe link at the bottom. One click and you are off the list — you do not have to explain why, and you do not have to sign in.
Leaving is not restricted to that link. Reply to any of our emails, or write to security@gdsinstruments.com, and we will take you off. We will not turn down a request to be removed because it arrived the wrong way.
Unsubscribing deletes your address. It does not hide it or mark it inactive.
Reporting a problem
The same address, security@gdsinstruments.com, is where to report a security problem in one of our products. A person reads it, not an automated system. Our vulnerability reporting policy sets out what to include and what happens after you send it.
What you will get
- One email per advisory we publish, at the same time it goes on this page.
- A further email if we revise an advisory in a way that changes what you need to do.
- Nothing else. No newsletters, no product announcements, no “while we have your attention”.
If you would rather not give us an address at all, use the Atom feed. It carries exactly the same advisories and tells us nothing about you.
Products no longer supported
We do not publish advisories for products past the end of their support period, and we do not issue security updates for them. If you are running one, see product support periods for the upgrade path.