We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

How to Report Potential Product Security Vulnerabilities

Need Help?

Privacy Policy

Live Chat

Protecting the Security of Our Products


At Microchip, we make product security a top priority. While strong security practices significantly reduce risk, no system or product can be completely immune to attack. We take all reports of potential security vulnerabilities seriously and work diligently to investigate, assess and address validated issues.

Our Product Security Incident Response Team (PSIRT) is responsible for receiving, reviewing, analyzing and responding to reports of potential security vulnerabilities that affect our products, including associated hardware, software, firmware and tools. Upon receiving a report, our team evaluates the issue and determines the appropriate course of action to mitigate any potential impact.

Responsible Disclosure Policy


We follow a coordinated vulnerability disclosure process and encourage responsible reporting from security researchers, customers and partners. Our approach is based on the CERT® Guide to Coordinated Vulnerability Disclosure and establishes clear expectations for collaboration throughout the vulnerability management process.

Reporting a Security Vulnerability


If you believe you have discovered a security vulnerability affecting our product, service or solution, please report it to our PSIRT team as soon as possible. Providing detailed and accurate information helps us assess and address issues more effectively.

Follow These Steps to Report a Potential Security Vulnerability


If the vulnerability affects a product, service or solution, send an email in English only to psirt@microchip.com and include as much information as possible:

  • Your contact information
  • Product name with available version or revision numbers
  • Name of the individual who discovered the vulnerability
  • Date of discovery and details of how the issue was identified
  • Detailed technical description of the vulnerability
  • Description of potential exploitation methods
  • A Common Vulnerability Scoring System (CVSS) score if possible

Other Security Issues

For security issues not directly related to a product vulnerability, send an email to csirt@microchip.com and include:

  • Website URL or affected location
  • Vulnerability type (for example, XSS or injection)
  • Reproduction instructions
  • Proof of concept, Common Vulnerabilities and Exposures (CVE) information or exploit code
  • Potential impact

Secure Submission of Vulnerability Reports


Because vulnerability reports often contain sensitive information, we strongly recommend encrypting submissions using the PSIRT PGP/GPG public key before transmission.

PGP/GPG Fingerprint: 37F360C867D9307734F9F347F6E69F3437D74775

Encryption Resources

How We Respond to Vulnerability Reports


We follow a structured process to evaluate, prioritize and remediate reported vulnerabilities.

  1. Discovery

We receive the report and acknowledge receipt of the information provided.

  1. Triage

Our team reviews the report to determine whether our product is affected and whether sufficient information is available to begin an investigation.

  1. Analyze

If additional information is required, we work with the reporter to gather the necessary details. Once sufficient information is available, a comprehensive technical investigation is conducted. Vulnerabilities are assessed using the latest CVSS methodology and may be assigned a CVE identifier when appropriate.

  1. Remediation

When a vulnerability is verified, we develop and implement appropriate corrective actions to address the issue.

  1. Disclosure

Where appropriate, we communicate information about verified vulnerabilities and remediation measures through security advisories and bulletins.

Cyber Resilience Act (CRA) Reporting Obligations

As of September 11, 2026, the European Union CRA requires manufacturers of products with digital elements placed on the EU market to report certain cybersecurity events to the relevant authorities, such as national Computer Security Incident Response Teams (CSIRTs) and ENISA.

Reportable Events

Under the CRA, the following events shall require regulatory reporting:

Actively Exploited Vulnerabilities

Vulnerabilities in products with digital elements for which there is reliable evidence that they are being exploited by a malicious actor

Severe Incidents

Incidents that have a significant impact on the security, availability, authenticity, integrity or confidentiality of a product with digital elements

CRA Reporting Timeline

Once we become aware of an actively exploited vulnerability or severe incident, the following reporting obligations apply:

Early Warning

Submitted within 24 hours of becoming aware of the event

Initial Notification

Submitted within 72 hours of becoming aware of the event and includes an initial assessment and available technical information

Final Report

  • For actively exploited vulnerabilities: No later than 14 days after a corrective measure becomes available
  • For severe incidents: Within one month after the 72-hour notification

Regulatory Reporting

CRA notifications are submitted through the CRA Single Reporting Platform (SRP). The platform enables manufacturers to submit a single notification that is distributed to the relevant national CSIRTs and ENISA.

Our Commitment

We maintain established vulnerability management, incident response and coordinated disclosure processes to support timely assessment, remediation and communication of cybersecurity issues. Where required, actively exploited vulnerabilities and severe security incidents will be reported in accordance with applicable CRA obligations.

Security Advisories and Vulnerability Disclosures


We publish security advisories for verified vulnerabilities to help customers understand affected products, severity ratings and available remediation guidance. Browse the latest PSIRT advisories and disclosures below.

Our Responses to Reported Vulnerabilities


Click here to Subscribe to Product Security Vulnerabilities Report.

Stay Informed


Subscribe to Vulnerability Notifications

Stay informed about newly disclosed vulnerabilities, product security advisories and remediation information by subscribing to our Product Security Vulnerability Reports.

Wireless Stacks Vulnerability Response

Media Inquiries


For media-related questions regarding the security of our products, please contact PR@microchip.com.

Live Chat

Need Help?

Privacy Policy