Vulnerability Disclosure Policy
pursuant to the Cyber Resilience Act (EU) 2024/2847
Last updated: 2026-08-31
Report a vulnerability or anomaly
The security of our products is a high priority for the KION Group.
If you discover a potential vulnerability, a security flaw or unusual behavior in one of our products, please let us know – via the form or by e-mail. Every report is handled confidentially.
How to report Report a vulnerability or anomaly
How to report Report a vulnerability or anomaly
Report potential vulnerabilities and anomalies by e-mail to our Product Security Incident Response Team. Every report is handled confidentially.
Please provide us with the following information:
- Affected product, component or service (if applicable, incl. name of model & vehicle identification number),
- Version / Build,
- A description of your observation,
- Steps to reproduce (where possible),
- Any indication of active exploitation (if known),
- Supporting material such as screenshots or logs,
- Your contact details (optional, if you wish to remain anonymous).
Please do not submit credentials or third-party personal data.
You will receive an acknowledgement of receipt and be kept informed of the status.
Processing Procedure
Our Vulnerability Handling Process
KION follows a structured, transparent four-step process to ensure that every reported vulnerability is reviewed, resolved, and communicated.
We only publish details once a solution is available (Coordinated Vulnerability Disclosure).
We handle all reports promptly and transparently.
You submit a potential vulnerability through the reporting channel – with sufficient detail to enable replication and assessment (see information above).
We review legitimacy, authenticity, impact and scope and determine severity using recognized systems such as CVSS; we may contact you for clarification.
The responsible product or service team remediates confirmed vulnerabilities, prioritising them according to risk, complexity, and safety relevance. Temporary mitigations are implemented where necessary.
Once the remediation process is complete, we will inform you of the outcome and notify the relevant authorities where required. We will also publish a security advisory to inform affected customers and users.
Scope and Safe Harbor
What you can report
- Vulnerabilities in products, software, apps and online services of the KION Group,
- Security vulnerabilities in networked components such as telematics, IoT, and interfaces,
- Actively exploited vulnerabilities and security incidents,
- Anomalies where the security relevance is unclear.
Safe Harbor
KION agrees not to pursue claims against reporting parties related to disclosures submitted to us provided that::
- the reporting party does not cause harm to KION, our customers, or others;
- the reporting party does not compromise the confidentiality, integrity, availability or safety of our customers' operation or of our services;
- the reporting party does not violate any criminal law;
- the reporting party publicly discloses vulnerability details only after KION confirms completed remediation of the vulnerability.
Security Events
KION documents closed security events here – confirmed vulnerabilities and severe incidents – with affected products, severity and resolution.
According to Article 14 of the EU Cyber Resilience Act (CRA), we publish information
- on actively exploited vulnerabilities (vulnerabilities for which credible evidence exists that they have been exploited without authorization) as well as
- on serious incidents (incidents that compromise or could compromise the security of a product with digital elements, or that have led or could lead to the infiltration or execution of malicious code),
as soon as the required assessment according to our Vulnerability Management Standard has been completed.
Only events that have been confirmed and classified as "actively exploited" or "severe" within KION's internal Vulnerability & Incident Management are published. This table will be updated with new findings; outdated entries will be marked accordingly.
We only publish events that have been confirmed and classified as 'actively exploited' or 'severe' in the internal Vulnerability & Incident Management system.
This table is updated as new information becomes available; outdated entries are marked accordingly.
| Identifier | Type | Product / area | Severity (CVSS) | CVE | Actively exploited | Status | Published | Advisory & fix |
|---|---|---|---|---|---|---|---|---|
| KION-SE-2027-014 | Vulnerability | Example product X, FW < 2.4.0 | Medium (5.4) | CVE-2027-00123 | No | Fixed | 2027-12-15 | Advisory (CSAF) · Fix |
Publication
In accordance with coordinated vulnerability disclosure principles, KION may publish a Security Advisory for validated vulnerabilities with potential external impact. These advisories are usually published once remediation measures, mitigations or compensating controls are available, unless earlier disclosure is required to mitigate risk.
Coordination and Acknowledgement
Where applicable, we coordinate the disclosure of information with our customers, partners and third-party suppliers. Security Advisories may acknowledge vulnerability reporters, provided they give their consent.
Format and Content
Security Advisories are provided in a structured format aligned with the Common Security Advisory Framework (CSAF) and may include:
- a unique advisory identifier
- affected products, services, and versions
- vulnerability description and impact
- severity assessment (e.g. CVSS)
- remediation, mitigation, or workaround information
- references to external identifiers (e.g. CVE), where applicable
The level of technical detail is limited to what is necessary to support effective risk management.
Processing of your data
We process the information you submit solely to handle your report.
Further information on the processing of personal data can be found in the KION Group Privacy Statement.