# Vendor Advisory Precedence Over Federal Exploitation Confirmation, June to September 2026

- **Artifact ID:** CHQ-SM-2026-017
- **Version:** v1.0
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/memoranda/chq-sm-2026-017
- **Machine-record SHA-256:** `e7a7ae8de8a991de5075bb8ad3d14123764173212e774188d10b36c8935a606a`

## Complete structured record

```json
{
  "id": "CHQ-SM-2026-017",
  "title": "Vendor Advisory Precedence Over Federal Exploitation Confirmation, June to September 2026",
  "descriptor": "Vendor Advisory Precedence Over Federal Exploitation Confirmation, June to September 2026",
  "issued": "2026-09-22",
  "classification": "Analytical",
  "status": "ISSUED",
  "version": "v1.0",
  "memo_type": "SM",
  "authority_level": "ANALYTICAL",
  "referenced_by": [
    "CHQ-SC-2026-010",
    "CHQ-P-2026-012"
  ],
  "inherits_from": "CHQ-SM-2026-013, CHQ-SM-2026-006",
  "related_artifacts": [
    "CHQ-SC-2026-010",
    "CHQ-P-2026-012"
  ],
  "doctrine_class": "Structural Memorandum",
  "precedent_constraints": [
    "CHQ-ASC-2026-002",
    "CHQ-ASC-2026-005"
  ],
  "governs_evidence_for": [
    "CHQ-SC-2026-010",
    "CHQ-P-2026-012 (counter-evidence note)",
    "Catalog-as-confirmation-record Position candidate"
  ],
  "citable_assertion": "For the period covered, vendor advisories were the earliest reliable exploitation signal available to defenders, while the federal catalog functioned as a confirmation record rather than a priority signal.",
  "purpose": "This memorandum documents the evidence on which SC-2026-010 was de-escalated from Strengthening to Emerging on 27 August 2026, so that the rating action, and any later re-escalation, can be reconstructed from the record rather than from the issue that reported it.",
  "statement": "",
  "observability": "",
  "boundary": "",
  "reliance_language": "",
  "reliance_boundary": "",
  "revision_history": "v1.0 (September 22, 2026): Initial issuance",
  "structural_sections": [
    {
      "heading": "EVIDENCE RECORD",
      "items": [
        "Oracle HTTP Server / WebLogic proxy, CVE-2026-21962 — vendor publication 20 January 2026; federal listing 24 August 2026; interval seven months; Oracle CPU advisory and CISA alert.",
        "Fortinet FortiOS, CVE-2025-25249 — vendor publication 13 January 2026; federal listing 9 September 2026; interval eight months; FortiGuard advisory and CISA alert.",
        "Progress LoadMaster, CVE-2026-8037 — vendor publication 4 June 2026; federal listing 7 August 2026; interval nine weeks; Progress bulletin and CISA alert.",
        "Citrix NetScaler, CVE-2026-8452 — vendor publication 30 June 2026; federal listing 26 August 2026; interval eight weeks; Citrix advisory and CISA alert.",
        "Citrix NetScaler, CVE-2026-19490 — vendor publication 19 August 2026; federal listing 9 September 2026; interval fifteen days; Citrix bulletin and CISA alert.",
        "Zimbra Collaboration, CVE-2026-73570 — vendor publication July 2026; federal listing 21 August 2026; interval approximately five weeks; Zimbra release note and CISA alert.",
        "Metabase, CVE-2026-72898 — vendor publication 6 August 2026; federal listing 11 August 2026; interval five days; Metabase advisory and CISA alert.",
        "Documented reversals of a vendor assessment in the same window: none. Ledger under the assessment-event unit at de-escalation: two reversals (Microsoft and Oracle, both before July), five vindications, and seven vindication-class chronologies added since.",
        "Validation test-set linkage: Cisco FMC CVE-2026-20131 — exploitation 26 January 2026, disclosure 4 March 2026, a 36-day pre-disclosure interval — is included from ASC-005's derivation alongside FortiClient EMS and PaperCut."
      ]
    },
    {
      "heading": "WHAT THE EVIDENCE ESTABLISHES",
      "content": "Across the review cycles concluding 13 and 27 August, every audited catalog entry carried a vendor advisory linked at listing, and vendor publication preceded federal confirmation by intervals from five days to eight months. The condition's downward criterion (two consecutive qualifying cycles) was met on this evidence."
    },
    {
      "heading": "WHAT IT DOES NOT ESTABLISH",
      "content": "Advisory precedence is not fix completeness: PaperCut (same-day disclosure, first patch bypassed within a day), N-central (mandatory hotfix after an incomplete patch), and Oracle (January fix revisited in July) show reliable signals with unstable remediation. The memorandum records the two axes separately and does not net them."
    },
    {
      "heading": "RELATIONSHIP TO DERIVED ARTIFACTS",
      "content": "SC-2026-010 cites this memorandum for its reset-era baseline. CHQ-P-2026-012 (Vendor Security Attestations Cannot Serve as Evidence of Operational Security State) receives a counter-evidence note citing this memorandum: attestations and advisories are different artifacts, and the Position stands, but the advisory record runs against the Position's spirit and the note is owed."
    }
  ],
  "revision_conditions": "Revised when three new documented reversals accrue after the de-escalation (the re-escalation trigger), or when the chronology test itself is amended under CGS-4.",
  "attestation": "This memorandum records that, for the period covered, vendor advisories were the earliest reliable exploitation signal available to defenders, and that the federal catalog functioned as a confirmation record rather than a priority signal."
}
```
