We will dive into any security related issue as long as your Magento version is still supported by Magento.
Please e-mail us directly at [email protected] or use the security issue template on GitHub. A security issue gets the highest priority assigned and a reply regarding the vulnerability is given within a typical 48 hours. Thank you!