Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

Published research and coordinated disclosures.

Independent vulnerability research by the specialists who run our client engagements. Each advisory below was responsibly disclosed, fixed in production, and is publicly verifiable.

RSS feed

01

Advisories

2023–2026
6
  1. 01

    A connection is not an exploit: what 27 days of honeypot traffic actually contained

    Internet-facing services (RDP, SMB, SSH, web, VoIP)

    Honeypot reports trade in enormous numbers. Across 27 days OffSeq's Mirage fleet logged 5.4 million events carrying a CVE label – and 99.9% were doorknob-rattling: brute-force logins and port scans, not exploitation. Strip the noise and the real signal is 3,572 actual exploit payloads – a sharp set of web CVEs from 2017 to 2023, led by a five-year-old Exchange bug, and one botnet still typing an eight-year-old SSH key by hand.

    Honeypot field report

    2026
  2. 02

    Cross-instance configuration poisoning in X-Road

    X-Road Security Server (< 7.8.2)

    X-Road Security Servers wrote federated global-configuration parts to disk based on the ecosystem identifier carried inside each part, without verifying it matched the actual source. A malicious federation partner could serve a SHARED-PARAMETERS part naming a victim ecosystem – signed with the victim’s own key – and overwrite its authoritative trust configuration, gaining persistent control and the ability to impersonate any of the victim’s members and Security Servers.

    Insufficient verification of data authenticity (CWE-345, CWE-346)

    CVSS 8.0 High GHSA-c5gr-pcm6-828r 2026
  3. 03

    Pre-authentication denial of service in X-Road signature verification

    X-Road Security Server (< 7.8.2)

    The hash-chain verifier in X-Road’s batch-signature handling had no cycle detection, depth limit or cap on resolved steps, and the attacker-controlled chain was resolved before signature and certificate checks. A registered ecosystem member could send a small crafted request (a few KB) to trigger exponential CPU use or unbounded recursion, exhausting processing threads and disrupting the data-exchange service before authentication.

    Uncontrolled resource consumption (CWE-400)

    CVSS 6.5 Medium GHSA-rc33-88jw-c5jp 2026
  4. 04

    Command injection fixed in Estonia’s national eID software

    DigiDoc4 – Estonia’s official eID signing application

    DigiDoc4’s file-manager integration constructed shell commands using unsanitised filenames. A specially crafted filename could execute arbitrary code when a user selected the file for signing or encryption. The issue affected software used for legally binding electronic signatures.

    OS command injection (CWE-78)

    Critical 2026
  5. 05

    SWQL injection in SolarWinds Platform

    SolarWinds Platform (≤ 2024.1 SR 1)

    A query-language injection vulnerability allowed an attacker to manipulate back-end database queries in the SolarWinds Platform. It was identified during penetration testing for the NATO Communications and Information Agency.

    SQL / SWQL injection (CWE-89)

    CVSS 7.5 High CVE-2024-28996 2024
  6. 06

    Cross-site scripting vulnerability in Oracle Enterprise Command Center

    Oracle E-Business Suite – ECC Framework

    An unauthenticated attacker could obtain unauthorised read and update access to data in the framework and connected Oracle products. Oracle fixed the issue in its October 2023 Critical Patch Update.

    Cross-site scripting (CWE-79)

    CVSS 6.1 Medium CVE-2023-22107 2023
  7. 07

    SQL injection affecting customer data, responsibly disclosed

    International company (responsibly anonymized)

    An SQL injection vulnerability could have exposed customer data. It was reported through a responsible-disclosure process and fixed promptly. CERT.LV has publicly acknowledged our founder’s contributions to the security of Latvia’s internet space.

    SQL injection

    High 2023
  8. 08

    threat-finder – open-source runtime CVE scanner

    OffSeq open-source tools

    A runtime vulnerability scanner that identifies CVEs affecting services currently running on a host and prioritises them by network exposure. It is part of the public toolset we develop and use in engagements.

    Research & tooling

    2025

Have similar exposure in your environment?

[email protected] +371 2256 5353