Our engineers find vulnerabilities for a living. Most of what we report to clients is about how their systems are built and configured. Sometimes the flaw is in the product itself. When that happens, we take it to the vendor, work through coordinated disclosure, and the issue receives a CVE identifier through MITRE.
12 CVEs to date, across ManageEngine, PRTG Network Monitor, Nagios XI, and Rock RMS. Every one came from real engagement work — not a lab exercise.
Every CVE listed here was discovered during active penetration testing work, not independent research disconnected from real-world environments.
| CVE ID | Product | Year |
|---|---|---|
| CVE-2026-36748 | Rock RMS | 2026 |
| CVE-2022-35739 | PRTG Network Monitor | 2022 |
| CVE-2022-26777 | ManageEngine Remote Access Plus | 2022 |
| CVE-2022-26653 | ManageEngine Remote Access Plus | 2022 |
| CVE-2022-25373 | ManageEngine Support Center Plus | 2022 |
| CVE-2022-25245 | ManageEngine Asset Explorer | 2022 |
| CVE-2022-24681 | ManageEngine ADSelfService Plus | 2022 |
| CVE-2021-38156 | Nagios XI | 2021 |
| CVE-2021-31813 | ManageEngine Applications Manager | 2021 |
| CVE-2021-29643 | PRTG Network Monitor | 2021 |
| CVE-2021-28382 | ManageEngine Key Manager Plus | 2021 |
| CVE-2021-27956 | ManageEngine ADSelfService Plus | 2021 |
We report what we find to the vendor before we publish anything. Closing the hole comes first. The writeup comes second.
Report to the vendor
We contact the vendor directly with full technical details before any public disclosure. They get first knowledge, and time to build a fix.
Coordinate the timeline
We work with the vendor to understand fix complexity and agree on a disclosure timeline that gives customers time to patch.
Confirm the fix
We verify the fix is in place and effective before any public release. A patch that doesn't close the hole isn't a fix.
Publish the technical writeup
Only after the fix is confirmed do we publish our technical analysis, so other defenders understand the attack pattern and can validate their own exposure.
Bypassing a CSP and WAF with Google Tag Manager. An unsafe CSP exemption for GTM turns any script hosted on googletagmanager.com into a usable attack vector.
The engineers who discover vulnerabilities in shipping products are the same ones who test your systems. When something looks unusual, they dig until they understand it — not until a checklist says they can stop.
Original research experience means our testers approach your environment with the same mindset they bring to vendor product analysis: look for what should not be possible.
View Trust Center for full credentialsThe engineers who find these flaws in shipping products are the same ones who test your systems. Schedule a call to discuss scope and get a fixed estimate.