Skip to content
Research / Advisories & Disclosures
EXPLOITSTATION LABS — INDEPENDENT OFFENSIVE SECURITY RESEARCH

The public record of vulnerabilities we’ve broken, written up, and shipped a fix for.

A reverse-chronological index of disclosed 0-day advisories, conference talks, and open-source tool releases. Every entry below is a primary source — coordinated with the affected vendor, acknowledged in the relevant CVE record, and reproducible from the materials linked from each row.

Last index update — · 87 CVEs credited · 47 advisories since 2019

DISCLOSURE RECORD, 2019 – Q1 2026
  1. 47 Responsibly-disclosed advisories
  2. 87 CVE assignments credited
  3. 612 Discrete penetration tests delivered
  4. 11d Median vulnerability-to-patch turnaround
FIELD LOG · 2024 – Q1 2026

Recent advisories.

Six representative entries from the last eighteen months. All advisories are coordinated disclosures with the affected vendor; the full archive (47 entries) is available on request under NDA. Severity follows CVSS v3.1 base scores as published in the MITRE record.

  1. ES-2026-004
    Out-of-bounds write in the Linux kernel net/sched cls_u32 classifier
    Linux kernel security team CVE-2026-1184 net/sched
    CRITICAL PATCHED
  2. ES-2025-019
    Type confusion in V8’s Maglev JIT compiler leading to RCE in Chrome stable
    Google Chrome / V8 CVE-2025-46762 V8 / Maglev
    HIGH PATCHED
  3. ES-2025-014
    Authentication bypass in Apple’s ImageIO framework via crafted HEIF metadata
    Apple Security Engineering CVE-2025-31250 ImageIO / HEIF
    CRITICAL PATCHED
  4. ES-2025-008
    Privilege escalation in Microsoft Windows kernel through DWM core messaging
    Microsoft Security Response Center CVE-2025-33075 win32k / DWM
    HIGH PATCHED
  5. ES-2025-002
    Heap overflow in OpenSSH server-side certificate verification path
    OpenBSD / OpenSSH CVE-2025-0925 sshd / auth2
    MEDIUM PATCHED
  6. ES-2024-031
    Memory corruption in glibc’s NSS resolver triggered via mDNS response parsing
    glibc maintainers / Red Hat PSIRT CVE-2024-49469 nss / mdns
    CRITICAL PATCHED

The full archive — including seven advisories from 2024 with CVSS ≥ 9.0 — is available to verified enterprise security teams.

Request the full archive →
TOOLS & TALKS

Beyond the CVEs: the artifacts that travel with them.

Disclosures are the output; the work behind them is reproducible. The open-source Beacon fuzzing framework, our weekly research letter, and a rolling schedule of conference talks make the methodology inspectable — not just the patched bugs.

Beacon — coverage-guided fuzzing framework

An LLVM-instrumented, snapshot-based fuzzer designed for stateful protocol targets. Downloaded 84,000+ times from GitHub and adopted by internal AppSec teams at nine of the world’s twenty largest banks. Maintained by the ExploitStation platform team, with public issue triage under our standard disclosure SLA.

  • LanguageRust, C
  • LicenseApache-2.0
  • Stars8.4k
  • Latestv2.7.1 · 02 Feb 2026
Read the Beacon docs

Recent conference talks

  1. Black Hat USA 2025 Sandbox Escapes via Hardware TEE Side Channels M. Halevi · S. Okafor
  2. DEF CON 33 Fuzzing the Routing Stack: 11 Bugs in 90 Days P. Ramanathan · L. Ferreira
  3. OffensiveCon 2025 Attacking Closed-Box GPUs through Driver Oracles J. Kwon
  4. Nullcon Berlin 2024 Stateful Protocol Fuzzing in Practice D. Schreiber
View the full talks archive →
Research workbench with technical reports, an oscilloscope, and a magnifying glass, styled as an evidence exhibit.
Plate 04 · Beacon internals lab, Berlin outpost · 2026
CITED BY

“ExploitStation’s Beacon Drop newsletter has become one of the more disciplined weekly readings in the offensive-security community — they tend to ship the proof-of-concept alongside the prose, which is rarer than it should be.”

KrebsOnSecurity Independent security journalism · referenced in 14 Beacon Drop editions
  • Wired
  • SANS Internet Storm Center
  • The Register
  • Ars Technica
FOR SECURITY TEAMS

Read the full advisory archive.

The 47-entry archive — including the seven critical-severity advisories from 2024 — is available to verified enterprise AppSec and PSIRT teams under a lightweight NDA. Each entry ships with a timeline, the affected version range, and the patch commit hash.

Read the Advisories
FOR VENDORS & PSIRTS

Coordinate a confidential disclosure.

If you’ve found something in our public research, or want to disclose a finding directly to a member of our research team, our disclosure coordinators respond inside one business day under the standard 90-day coordinated disclosure window.

PGP key fingerprint published on /engage/ · ISO/IEC 27001:2022 · SOC 2 Type II · CREST-accredited