This page lists the security advisories EMRI has published for its products. An advisory describes a vulnerability, says which product versions are affected by it, and tells you what to do about it.
Advisories are public. You do not need an account, a login or a support contract to read them.
Advisories by product
Each product has one advisory page carrying every advisory published for it, newest first.
All advisories, newest first
EMRI has not published any security advisories yet. When we publish one, it is listed here with its identifier, title, product, publication date and severity, and links to the advisory on its product page.
What an advisory tells you
Every EMRI advisory carries at least the following:
- An advisory identifier in the form EMRI-SA-YYYY-NNN
- The affected product, and the versions that are affected
- A severity, given as a CVSS v3 base score and the full CVSS vector
- A plain-language description of the vulnerability, and its impact — what an attacker could achieve
- Remediation: the version that fixes it, where a fix exists, and how to obtain that version
- Interim mitigations you can apply now, where any apply
- The date the advisory was published
Some advisories are published before a fix is available. Those carry mitigations and no fixed version, and say so explicitly. An advisory that names no fixing release is not an incomplete advisory — it means there is not yet a release to name.
Advisory identifiers and permanent links
Every advisory lives on its product’s advisory page and has its own permanent link, made from that page’s address and the advisory identifier — for example /security/advisories/autopilot-mini-display#emri-sa-2026-001. That link does not change. You can cite it, bookmark it, or record it in a vessel maintenance log and expect it to keep working.
Advisories are amended in place rather than republished. When we change one — because a fix has landed, a mitigation has been superseded, or a vulnerability database identifier has been assigned — the link and the identifier stay the same, the last-updated date changes, and the advisory carries a note saying what changed. We do not delete or withdraw published advisories, and we do not remove them when a product version reaches end of life.
Reporting a vulnerability
If you believe you have found a security vulnerability in an EMRI product or on this website, please tell us. Our coordinated vulnerability disclosure policy, the rules for good-faith research, and the report form are at emri.dk/security. You can also email security@emri.dk.