ExPatch LLC // Boston, MA // Authorized only

Authorized Offensive Security.

Red team operations, exploit development, and vulnerability research for teams that need proof, not theater. Every engagement starts with written scope and ends with evidence engineers can act on.

Written authorization Coordinated disclosure Engineer-ready evidence

Why teams trust it

Serious security work needs visible restraint

ExPatch is built for authorized offensive work: clear scope, precise execution, and findings that survive engineering review.

01

Authorization first

Rules of engagement are established before testing begins.

02

Proof over noise

Findings include reproduction, impact, and practical fix guidance.

03

Research discipline

Vulnerabilities are handled through coordinated disclosure.

04

Operator mindset

Testing follows realistic adversary paths, not checklist theater.

Capabilities

Built for high-consequence targets

The work is offensive, but the operating model is controlled: no unauthorized testing, no vague handoff, no findings without evidence.

Process

A controlled offensive loop

The process is designed to produce decisions: what happened, why it mattered, and exactly what needs to change.

01

Scope

Define authorization, assets, objectives, safety limits, and communication rules.

02

Emulate

Operate against the routes a real adversary would prefer, with measured pressure.

03

Prove

Validate exploitability and impact with clean artifacts, timelines, and reproduction.

04

Harden

Support remediation, retest critical paths, and leave the team with usable evidence.

Coordinated disclosure

Research ledger

Every vulnerability is reported to the vendor first and published only after coordinated disclosure.

IdentifierProductCVSSSeverityPublishedStatus
CVE pendingTelegram Desktop (tdesktop)8.2High2026-09-12Fixed
CVE-2026-65494Dokan Pro (WordPress)7.1High2026-08-13Coordinated
CVE-2026-65493Dokan Pro (WordPress)7.5High2026-08-13Coordinated
CVE-2026-54825wpDataTables Premium (WordPress)9.3Critical2026-08-13Fixed
CVE-2026-54682DiscordChatExporter8.2High2026-08-13Fixed
CVE-2026-54681DiscordChatExporter4.1Medium2026-08-13Fixed
CVE-2026-17543PHP ext/pgsql (php-src)9.8Critical2026-06-02Fixed

Engagements

Bring the systems that need real scrutiny.

Red team, exploit development, or focused vulnerability research for software and environments you own or are authorized to test.

// secure channel — PGP on request