Welcome to the Inductive Automation Trust Portal
Thousands of companies worldwide depend on Ignition
- See Founder’s Message and Company Leadership
- Customers, Case Studies, Projects, Discover Gallery
- SDLC guide. (Duo/CrowdStrike) case studies
- ** Subscribe to Trust Center Updates ** (below)
- Vuls/contact: security@inductiveautomation.com (PGP)
Trust Center Updates
EU Cyber Resilience Act (CRA)
Inductive Automation and the EU Cyber Resilience Act
Inductive Automation is committed to meeting the requirements of the EU Cyber Resilience Act (CRA), a condition of continuing to sell Ignition in the EU. We take this seriously. We believe the work will benefit every Ignition customer, not just those in the EU.
Initial CRA compliant version of Ignition
We will offer an initial CRA compliant version of Ignition ahead of the December 11, 2027 deadline. We'll announce the specific version as plans are finalized. This will be a standard Ignition release, not a separate product: same licensing, same costs.
For customers, the path is simple. CRA requirements apply to versions of Ignition placed on the market after December 11, 2027, so you can keep running earlier versions for as long as needed. When you're ready to upgrade, a CRA compliant version will be available. No disruption is required.
Vulnerability disclosure and reporting
Inductive Automation already operates a coordinated vulnerability disclosure program. We coordinate directly with CISA. Our findings are formally scored and cataloged in the NIST National Vulnerability Database for the broader security community. We are prepared to meet the ENISA coordinated vulnerability disclosure reporting requirements when they take effect in September 2026, in addition to these current practices.
Long term support and free security updates
We're formalizing how Long Term Support will work with our upcoming Ignition 2027 release, and we're excited about what it will bring. We know our customers plan on long horizons, and we want to make that possible, with periodic upgrades along the way. Whatever form LTS takes, one key detail is already settled: CRA compliant versions of Ignition will receive free security updates as required by the CRA, for a minimum of five years from market placement, regardless of support contracts or LTS status.
Getting it right
We're working with qualified outside consultants to make sure our CRA program is done right and on schedule. We'll share more details here as milestones are reached.
Java Runtime (JRE) Security Advisories
Background
Ignition by Inductive Automation does not use Oracle Java. Ignition bundles a commercially licensed distribution of Azul Zulu JDK, which receives quarterly security updates aligned with the Java Critical Patch Update (CPU) cycle. Once a new Azul Zulu release is available and validated, Inductive Automation integrates and tests it prior to inclusion in an Ignition release.
The following CVEs were identified in Java versions prior to the April 21, 2026 release and could apply to Ignition 8.3.6 and earlier. None are tested or acknowledged Ignition-specific vulnerabilities. Issues of that nature are handled with priority and receive a dedicated security advisory and CVE assignment under Inductive Automation, and should be reported to security@inductiveautomation.com.
JRE Affected CVEs
| CVE | Component | Remote Exploit (no auth) | CVSS Base | Attack Vector |
|---|---|---|---|---|
| CVE-2026-22016 | JAXP | Yes | 7.5 | Network |
| CVE-2026-20652 | JavaFX (WebKitGTK) | Yes | 7.5 | Network |
| CVE-2026-34282 | Networking | Yes | 7.5 | Network |
| CVE-2026-22013 | JGSS | Yes | 5.3 | Network |
| CVE-2026-22021 | JSSE | Yes | 5.3 | Network |
| CVE-2026-23865 | 2D (FreeType) | No | 5.3 | Local |
| CVE-2026-22018 | Libraries | Yes | 3.7 | Network |
| CVE-2026-22008 | Libraries | Yes | 3.7 | Network |
| CVE-2026-22007 | Security | No | 2.9 | Local |
| CVE-2026-34268 | Security | No | 2.9 | Local |
| CVE-2026-22003 | Hotspot | No | 6.0 | Local |
Resolution
These vulnerabilities are not known to affect Ignition. However, Inductive Automation will address the underlying vulnerabilities by including Azul Zulu Java 17.0.19 in Ignition 8.3.8. Customers running security scans against Ignition 8.3.6 or earlier may observe these CVEs flagged against the bundled JVM. This advisory can be referenced in scan exception documentation.
Sources: Azul Zulu CVE History | April 2026 Release Notes (PDF)
CVE-2025-13911 (Ignition Windows Default)
If you noticed Ignition CVE-2025-13911, you're probably wondering what this means for you.
The default Ignition installation on Windows grants greater operating system permissions than is needed in most cases. An Ignition administrator importing malicious project resources could lead to a system level compromise or other significant effects.
This Tech Advisory contains more information. Steps #1-#3 correct the issue. The Ignition Security Hardening Guide has been updated with “Appendix A - Restrict the Ignition Service Security” with additional recommendations.
Feel free to reach out to Inductive Automation if you have any additional questions.
Ignition Software: Library Vulns / Updates
Bouncy Castle: CVE-2025-14813, CVE-2025-8916, CVE-2026-0636, and CVE-2026-5588
Ignition 8.1.54 and 8.3.8 bundle Bouncy Castle 1.78.1, which appears in the affected range for CVE-2025-14813, CVE-2025-8916, CVE-2026-0636, and CVE-2026-5588. Dependency scanners flag the library on that basis. Inductive Automation has reviewed these against Ignition 8.1 and 8.3 code and confirmed none is exploitable in Ignition.
CVE-2025-14813 (GOST 28147 CTR): Ignition does not use the GOST cipher in any mode. No product code references it, and every cipher operation in the product uses a fixed AES, 3DES, or RSA algorithm. The affected class ships in the library but is not reachable from Ignition's own code.
CVE-2025-8916, CVE-2026-0636, and CVE-2026-5588: each depends on a Bouncy Castle code path that Ignition does not use. Certificate validation and signature verification run through the JDK, not the affected components.
Inductive Automation is updating Bouncy Castle to 1.85+. Detailed per CVE analysis is available under NDA. No action needed. A Trust Center post will be submitted when fixes are available, expected on the next normal release cycle.
CVE-2025-13913 (Ignition file import)
Ignition software versions prior to 8.3.0 are affected by CVE‑2025‑13913. A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code. This issue was responsibly reported by security researchers at Meta. No exploits are known to exist in the wild.
Following the guidance in Appendix A – Restrict the Ignition Service Security of the Ignition Security Hardening Guide is considered best practice and reduces the risk of exploitation by limiting the privileges available to the Ignition service.
Clarification: Early public descriptions of CVE‑2025‑13913 incorrectly stated that “Inductive Automation Ignition Software is vulnerable to an unauthenticated API endpoint exposure that may allow an attacker to remotely change the ‘forgot password’ recovery email address.” This was inaccurate and has since been corrected.
Questions, concerns, or reporting exploitation instances may be directed to security@inductiveautomation.com.





