Back Issues This Week → Current Issue → Popular →

All issuesVolume 334, Issue 3IT Vendor NewsRed Hat

Understanding Security Embargoes At Red Hat

Red Hat, Thursday, January 22nd, 2026

Within Red Hat's Coordinated Vulnerability Disclosure (CVD) framework, an embargo is a strictly-defined window of time during which a security vulnerability is known only to a small group of trusted parties before being made public, including the vulnerability reporter and the relevant upstream community and partners.

Why are embargoes necessary?

The primary goal of an embargo is customer protection. If a severe vulnerability is disclosed immediately upon discovery by way of "full disclosure" without an available patch, malicious actors have a window of opportunity to exploit systems while users are defenseless. An embargo provides vendors the necessary time to develop, test, and package a fix, as well as coordinate with the trusted parties mentioned above.

more →  ·  More from Red Hat →