Research · Explainer

Coordinated Disclosure, Explained: How Security Bugs Go From Report to Patch

A vulnerability report starts a clock. Who gets told, how long they get, and when the details go public — the rules that turn private findings into patched systems.

A visitor signs in at the Googleplex, Google's headquarters in Mountain View, California — home of Google's Project Zero security research team.
A visitor signs in at the Googleplex, Google’s headquarters in Mountain View, California — home of Google’s Project Zero security research team, whose 90+30 deadline policy anchors modern disclosure practice.

Photo: Erik Möller, Public domain, via Wikimedia Commons

Every patch notice HackedWire covers — Cisco’s NX-OS advisories, SonicWall’s SMA1000 hotfixes, Atlassian’s security bulletins — is the visible end of a process that started weeks or months earlier, when someone reported a bug to the vendor. Coordinated vulnerability disclosure (CVD) is the set of norms governing that interval: private reporting first, a deadline for the fix, then public details.

The baseline: 90+30

Google’s Project Zero, the research team whose policy is the industry reference point, publishes its deadlines openly. From the Project Zero vulnerability disclosure policy: “Project Zero follows a 90+30 disclosure deadline policy, which means that a vendor has 90 days after Project Zero notifies them about a security vulnerability to make a patch available to users. If they make a patch available within 90 days, Project Zero will publicly disclose details of the vulnerability 30 days after the patch has been made available to users.”

The logic: 90 days gives the vendor a bounded window to build and ship a fix, and the additional 30 days gives users time to deploy it before technical details — useful to attackers — go public. If no patch appears within 90 days, the details go public at day 90 regardless, which is the pressure mechanism that makes the deadline credible.

Edge cases: grace periods and in-the-wild flaws

The policy has formal exceptions rather than informal ones. A 14-day grace period (extending disclosure to day 104, with details published at day 120) is available on request — a structured accommodation for vendors that need a little more time, not a veto over disclosure.

Actively exploited flaws — “in the wild” vulnerabilities — move on a different clock: a 7-day disclosure policy replaces the 90-day policy, because defenders need the details urgently when attacks are already underway. The 30-day post-patch window still applies, and the grace period shrinks to 3 days.

The Googleplex headquarters in Mountain View, California.
The Googleplex headquarters in Mountain View, California. Disclosure deadlines exist to balance vendor engineering time against defender urgency — 90+30 in the normal case, 7 days when exploitation is already underway.

Photo: Asoundd, CC BY-SA 4.0, via Wikimedia Commons

How it looks in practice: this week’s coverage

The machinery is visible in this week’s reporting. SonicWall’s advisory SNWLID-2026-0017 credited researchers Benoît Sevens and Brian Mariani for the flaws they reported — researcher attribution in a vendor advisory is coordinated disclosure working as intended. Atlassian disclosed CVE-2026-21589, watchTowr published technical details and a proof-of-concept the next day, and exploitation followed within hours — the compressed, high-stakes end of the timeline, where the gap between public details and attacker tooling can be vanishingly small. And Trend Micro’s Zero Day Initiative runs its own variant at Pwn2Own: vendors get 90 days post-contest before public disclosure of the demonstrated vulnerabilities.

The vendor’s side of the process

Coordinated disclosure is not just a researcher’s discipline. On the vendor side it means: acknowledging reports promptly, validating the flaw, assigning a CVE through its CNA role where applicable, building and testing a fix, shipping a security advisory with affected versions and remediation, and crediting the reporter. Cisco’s advisories and Atlassian’s bulletin for CVE-2026-21589 follow this shape: scope, severity, affected and fixed versions, and remediation guidance.

What the deadlines are for

Disclosure deadlines balance two risks. Without a deadline, vendors can sit on reports indefinitely and users stay exposed unknowingly. Without a private-reporting window, every flaw becomes a zero-day race the moment it is found, and defenders get no head start. The 90+30 structure — bounded private time, bounded deployment time, public details at the end — is the compromise the industry converged on, and the in-the-wild 7-day policy is the acknowledgment that compromise has limits when attacks are live.

No corrections have been published for this article.

About the author

Nina Petrova, Correspondent — beat: enterprise security & policy.