The public record of vulnerabilities we’ve broken, written up, and shipped a fix for.
A reverse-chronological index of disclosed 0-day advisories, conference talks, and open-source tool releases. Every entry below is a primary source — coordinated with the affected vendor, acknowledged in the relevant CVE record, and reproducible from the materials linked from each row.
Recent advisories.
Six representative entries from the last eighteen months. All advisories are coordinated disclosures with the affected vendor; the full archive (47 entries) is available on request under NDA. Severity follows CVSS v3.1 base scores as published in the MITRE record.
-
ES-2026-004
-
ES-2025-019
-
ES-2025-014
-
ES-2025-008
-
ES-2025-002
-
ES-2024-031
The full archive — including seven advisories from 2024 with CVSS ≥ 9.0 — is available to verified enterprise security teams.
Request the full archive →Beyond the CVEs: the artifacts that travel with them.
Disclosures are the output; the work behind them is reproducible. The open-source Beacon fuzzing framework, our weekly research letter, and a rolling schedule of conference talks make the methodology inspectable — not just the patched bugs.
Beacon — coverage-guided fuzzing framework
An LLVM-instrumented, snapshot-based fuzzer designed for stateful protocol targets. Downloaded 84,000+ times from GitHub and adopted by internal AppSec teams at nine of the world’s twenty largest banks. Maintained by the ExploitStation platform team, with public issue triage under our standard disclosure SLA.
Read the Beacon docsRecent conference talks
- Black Hat USA 2025 Sandbox Escapes via Hardware TEE Side Channels
- DEF CON 33 Fuzzing the Routing Stack: 11 Bugs in 90 Days
- OffensiveCon 2025 Attacking Closed-Box GPUs through Driver Oracles
- Nullcon Berlin 2024 Stateful Protocol Fuzzing in Practice
“ExploitStation’s Beacon Drop newsletter has become one of the more disciplined weekly readings in the offensive-security community — they tend to ship the proof-of-concept alongside the prose, which is rarer than it should be.”
- Wired
- SANS Internet Storm Center
- The Register
- Ars Technica
Read the full advisory archive.
The 47-entry archive — including the seven critical-severity advisories from 2024 — is available to verified enterprise AppSec and PSIRT teams under a lightweight NDA. Each entry ships with a timeline, the affected version range, and the patch commit hash.
Read the AdvisoriesCoordinate a confidential disclosure.
If you’ve found something in our public research, or want to disclose a finding directly to a member of our research team, our disclosure coordinators respond inside one business day under the standard 90-day coordinated disclosure window.