Live Chat
At Microchip, we make product security a top priority. While strong security practices significantly reduce risk, no system or product can be completely immune to attack. We take all reports of potential security vulnerabilities seriously and work diligently to investigate, assess and address validated issues.
Our Product Security Incident Response Team (PSIRT) is responsible for receiving, reviewing, analyzing and responding to reports of potential security vulnerabilities that affect our products, including associated hardware, software, firmware and tools. Upon receiving a report, our team evaluates the issue and determines the appropriate course of action to mitigate any potential impact.
If you believe you have discovered a security vulnerability affecting our product, service or solution, please report it to our PSIRT team as soon as possible. Providing detailed and accurate information helps us assess and address issues more effectively.
If the vulnerability affects a product, service or solution, send an email in English only to psirt@microchip.com and include as much information as possible:
For security issues not directly related to a product vulnerability, send an email to csirt@microchip.com and include:
Because vulnerability reports often contain sensitive information, we strongly recommend encrypting submissions using the PSIRT PGP/GPG public key before transmission.
PGP/GPG Fingerprint: 37F360C867D9307734F9F347F6E69F3437D74775
Encryption Resources
We follow a structured process to evaluate, prioritize and remediate reported vulnerabilities.
We receive the report and acknowledge receipt of the information provided.
Our team reviews the report to determine whether our product is affected and whether sufficient information is available to begin an investigation.
If additional information is required, we work with the reporter to gather the necessary details. Once sufficient information is available, a comprehensive technical investigation is conducted. Vulnerabilities are assessed using the latest CVSS methodology and may be assigned a CVE identifier when appropriate.
When a vulnerability is verified, we develop and implement appropriate corrective actions to address the issue.
Where appropriate, we communicate information about verified vulnerabilities and remediation measures through security advisories and bulletins.
As of September 11, 2026, the European Union CRA requires manufacturers of products with digital elements placed on the EU market to report certain cybersecurity events to the relevant authorities, such as national Computer Security Incident Response Teams (CSIRTs) and ENISA.
Under the CRA, the following events shall require regulatory reporting:
Actively Exploited Vulnerabilities
Vulnerabilities in products with digital elements for which there is reliable evidence that they are being exploited by a malicious actor
Incidents that have a significant impact on the security, availability, authenticity, integrity or confidentiality of a product with digital elements
Once we become aware of an actively exploited vulnerability or severe incident, the following reporting obligations apply:
Submitted within 24 hours of becoming aware of the event
Submitted within 72 hours of becoming aware of the event and includes an initial assessment and available technical information
CRA notifications are submitted through the CRA Single Reporting Platform (SRP). The platform enables manufacturers to submit a single notification that is distributed to the relevant national CSIRTs and ENISA.
We maintain established vulnerability management, incident response and coordinated disclosure processes to support timely assessment, remediation and communication of cybersecurity issues. Where required, actively exploited vulnerabilities and severe security incidents will be reported in accordance with applicable CRA obligations.
We publish security advisories for verified vulnerabilities to help customers understand affected products, severity ratings and available remediation guidance. Browse the latest PSIRT advisories and disclosures below.
| Technology | Description | Severity | Publish Date | Last Updated |
|---|
Stay informed about newly disclosed vulnerabilities, product security advisories and remediation information by subscribing to our Product Security Vulnerability Reports.
Learn about our Wireless Stacks Vulnerability Response.
For media-related questions regarding the security of our products, please contact PR@microchip.com.
Live Chat