AI News Feed
Market watch
Companies

Qi An Xin Wins Two CNNVD Awards for Vulnerability Management and Reporting

Qi An Xin received two CNNVD awards in Chengdu on Sept. 15, 2026, for collaborative software and hardware vulnerability management and vulnerability reporting. It was among the most awarded companies at the event, according to Leifeng.com.

The event was part of the 2026 National Cybersecurity Week Chengdu series. It was hosted by CNNVD and the Information Security Industry Branch of the China Information Industry Association and organized by China Information Security magazine. The event brought together representatives from national critical information infrastructure units, cybersecurity companies, basic software and hardware enterprises, and university research institutions. Its theme was AI for Good and Security with Principles. As a national information security vulnerability data platform, CNNVD is responsible for discovering, analyzing, and handling major cybersecurity vulnerabilities, and its annual awards represent the highest professional level in domestic vulnerability governance.

Qi An Xin received recognition in both collaborative management and reporting quality, reflecting its dual role as a discoverer and guardian in the vulnerability ecosystem, the report said. The two awards followed the company's continued status as a top-level Core Technical Support Unit for CNNVD, the highest level granted by the database, according to Leifeng.com. The company said the recognition reflects its full-chain vulnerability governance capabilities.

Qi An Xin has worked in the vulnerability field for more than a decade, building a system of technical teams that includes the Code Security Laboratory, Tiangong Laboratory, Wuji Laboratory, Xunfeng Industrial Control Security Laboratory, Threat Intelligence Center, and Butian platform, among more than ten teams. Its work covers software source code analysis, binary vulnerability mining, operating system kernel-level vulnerability discovery, and industrial control system security research. The company has reported more than one thousand zero-day vulnerabilities to authoritative platforms including CVE, CNNVD, CNVD, and NVDB, and has repeatedly received official acknowledgments from Google, Microsoft, Apple, Oracle, and Cisco.

In the first round of CNNVD vulnerability reward evaluations for 2026, Qi An Xin took six first-level contribution awards, the most among participating units. The company said its continued output of high-quality original vulnerabilities provides data support for early warning, analysis, and remediation at the national vulnerability database.

Qi An Xin applies the concept of collaborative management throughout the vulnerability governance lifecycle. In its own product security, it uses the Secure Development Lifecycle, or SDL, and has established a closed-loop process covering vulnerability discovery, repair promotion, verification, and review. At the industry level, its Butian vulnerability response platform has gathered more than 250,000 white-hat experts and received reports of more than 3.27 million vulnerabilities, connecting civilian security researchers with vendor repair systems and helping move vulnerabilities from discovery to remediation.

As AI reshapes cybersecurity offense and defense, vulnerability governance is moving from manual-driven to intelligence-driven work, according to the report. At the event, Qi An Xin showed intelligent vulnerability mining products including Qcode Agents. The company said these products have expanded from the application layer to operating system kernel-level and driver-level work, combining domain knowledge with a dynamic verification loop. Qi An Xin said it will continue to deepen coordination with CNNVD and industry parties and use AI to advance intelligent upgrading of basic software and hardware vulnerability governance.

Editor's Summary

Qi An Xin received two CNNVD awards in Chengdu on Sept. 15, 2026, for collaborative vulnerability management and vulnerability reporting. The recognition highlights its decade-long vulnerability research, reporting record, and use of AI-driven tools. It also points to the company's continued role in China's vulnerability governance ecosystem.