First published: Monday, December 13. Updated on Thursday, December 16.
On Friday, December 10, 2021, a critical security vulnerability designated CVE-2021-44228 was discovered in software used in many systems worldwide. Our security team (SOC) immediately got to work and reviewed all of our systems. In addition, we immediately reached out to our key partners.
On Thursday, December 15, 2021, our security team (SOC) alerted us to a new security vulnerability designated CVE-2021-45046. This vulnerability is related to the one mentioned earlier. The security team immediately began working on the issue and checked all of our systems for this new vulnerability. To the best of our knowledge, our systems are not currently vulnerable.
New information about this security vulnerability is emerging on an ongoing basis. We continue to actively monitor the situation and will take action as necessary. We are also continuing to consult with our suppliers and partners. We closely monitor all of our systems as a matter of standard practice. This notice will be updated as soon as further relevant information becomes available.
If you have any questions about this security vulnerability, please contact our Data Protection and Security Officer, Perry Bruins.