Skip to main content Scroll Top

Security advisories

This page lists the security advisories EMRI has published for its products. An advisory describes a vulnerability, says which product versions are affected by it, and tells you what to do about it.

Advisories are public. You do not need an account, a login or a support contract to read them.

Advisories by product

Each product has one advisory page carrying every advisory published for it, newest first.

All advisories, newest first

EMRI has not published any security advisories yet. When we publish one, it is listed here with its identifier, title, product, publication date and severity, and links to the advisory on its product page.

What an advisory tells you

Every EMRI advisory carries at least the following:

  • An advisory identifier in the form EMRI-SA-YYYY-NNN
  • The affected product, and the versions that are affected
  • A severity, given as a CVSS v3 base score and the full CVSS vector
  • A plain-language description of the vulnerability, and its impact — what an attacker could achieve
  • Remediation: the version that fixes it, where a fix exists, and how to obtain that version
  • Interim mitigations you can apply now, where any apply
  • The date the advisory was published

Some advisories are published before a fix is available. Those carry mitigations and no fixed version, and say so explicitly. An advisory that names no fixing release is not an incomplete advisory — it means there is not yet a release to name.

Advisory identifiers and permanent links

Every advisory lives on its product’s advisory page and has its own permanent link, made from that page’s address and the advisory identifier — for example /security/advisories/autopilot-mini-display#emri-sa-2026-001. That link does not change. You can cite it, bookmark it, or record it in a vessel maintenance log and expect it to keep working.

Advisories are amended in place rather than republished. When we change one — because a fix has landed, a mitigation has been superseded, or a vulnerability database identifier has been assigned — the link and the identifier stay the same, the last-updated date changes, and the advisory carries a note saying what changed. We do not delete or withdraw published advisories, and we do not remove them when a product version reaches end of life.

Reporting a vulnerability

If you believe you have found a security vulnerability in an EMRI product or on this website, please tell us. Our coordinated vulnerability disclosure policy, the rules for good-faith research, and the report form are at emri.dk/security. You can also email security@emri.dk.

Privacy Preferences
When you visit our website, it may store information through your browser from specific services, usually in form of cookies. Here you can change your privacy preferences. Please note that blocking some types of cookies may impact your experience on our website and the services we offer.