ITW EAE Support Center

Reporting a Security Vulnerability

ITW EAE develops its products using established engineering and quality processes that incorporate cybersecurity considerations throughout the product lifecycle. Security vulnerabilities identified through internal testing, customer feedback, or external reporting are evaluated, prioritized, and addressed as appropriate based on risk and product impact. While products placed on the European Union market prior to the Cyber Resilience Act (CRA) applicability dates may not be subject to all CRA conformity requirements, ITW EAE takes cybersecurity seriously and remains committed to addressing security concerns reported by customers, partners, and security researchers. We continuously evaluate opportunities to improve the security of both existing and future products. Products placed on the European Union market on or after December 11, 2027 will be developed and maintained in accordance with applicable Cyber Resilience Act requirements and associated cybersecurity obligations. The attached document details our full Coordinated Vulnerability Disclosure (CVD) policy. The link to submit a ticket is located in the CVD policy.