When a vendor whose equipment runs business phone systems and networks publishes a security advisory, a clock starts. Not on the vulnerability — that existed before anyone named it — but on the window between public disclosure and the point where exploitation becomes routine. That window is the whole game, and it is usually measured in days.
We have tracked those advisories internally for a long time. They are now published here as they arrive.
What's in the archive
Vendor-published advisories for the platforms we work with: MISA identifiers from Mitel, CVE references where the vendor provides them, the vendor's own severity rating, the affected products and versions, and a link to the source.
That is deliberately all of it. We do not re-score anything, and we do not add analysis the vendor did not publish. If Mitel calls something high, it reads high here.
Why we don't editorialise severity
A severity score describes a vulnerability in the abstract — how bad it could be, under assumptions about how the affected product is deployed. Whether it matters to you is a different question entirely, and it turns on things a score cannot see: which product you run, which version, whether it is reachable from the internet, and what sits in front of it.
Only the second question is actionable, and no blog post can answer it. So we publish the vendor's assessment unaltered and leave the rest where it belongs — a conversation about your environment, not a number on a page.
What we don't publish
We never name a client, and we never indicate who among the organisations we work with runs an affected product.
That is not a formality. An advisory page that lets a reader infer which business is exposed to a live vulnerability is a disclosure, not a service. What we publish describes products and versions. It does not describe anyone's estate.
About the dates
The archive opens with advisories the vendors published before today, dated to the vendor's own publication date rather than to the day we posted them.
An advisory's date is when it was disclosed. That date is the only thing that makes an archive useful for what archives are for — looking backwards and seeing when something became known. Restamping them to today would make the list look busier and make it worse.
So if you see advisories dated weeks or months back arrive together: that is deliberate. The dates are the vendors', and they stay that way.
What happens next
New advisories publish here as they are released. If you run Mitel, Fortinet, or anything else in the same neighbourhood, and you would rather not be the one watching vendor bulletins, that is the job we do.
