Why teams trust it
Serious security work needs visible restraint
ExPatch is built for authorized offensive work: clear scope, precise execution, and findings that survive engineering review.
Authorization first
Rules of engagement are established before testing begins.
Proof over noise
Findings include reproduction, impact, and practical fix guidance.
Research discipline
Vulnerabilities are handled through coordinated disclosure.
Operator mindset
Testing follows realistic adversary paths, not checklist theater.
Capabilities
Built for high-consequence targets
The work is offensive, but the operating model is controlled: no unauthorized testing, no vague handoff, no findings without evidence.
Red Team Operations Details
Objective-led adversary emulation across exposed systems, identity, cloud paths, and operational controls.
->We run the full intrusion cycle the way a real operator would: perimeter recon, initial access through the edge (VPN gateways, mail and file-sharing appliances), privilege escalation, lateral movement, and controlled exfiltration — the same chains our simulation globe plays out above, executed against your environment under written scope. Every objective ends in evidence: what we reached, how, and what would have stopped us.
Exploit Development Details
Deep technical validation where impact depends on memory safety, auth boundaries, chains, or reverse engineering.
->From a suspicious code path to a working primitive: parser differentials, escaping mismatches, deserialization chains, object injection. This is the craft behind our own advisories — a quoting desync in PHP's PostgreSQL layer (CVE-2026-17543), an unserialize sink turned into RCE in Dokan Pro (CVE-2026-65493). If we claim impact, we demonstrate it — in a lab, against the version you run.
Vulnerability Research Details
Focused research against products and environments you own, license, or are authorized to assess.
->Systematic audits of the components everyone else trusts by default. Our public ledger so far: PHP core (CVE-2026-17543), wpDataTables (CVE-2026-54825), Dokan Pro (CVE-2026-65493, CVE-2026-65494), DiscordChatExporter (CVE-2026-54681, CVE-2026-54682), Telegram Desktop (stored XSS, CVE pending) — every finding reproduced end-to-end, reported to the vendor first, published only after coordinated disclosure.
Remediation Retest Details
Validation after fixes land, with a clean line from exploit evidence to hardened behavior.
->A patch that blocks our PoC is not necessarily a fix. We return after remediation, re-run the original chain, and probe the adjacent code paths for variants — the incomplete fix is its own vulnerability class (one of our CVEs is exactly that). You get a verdict an engineer can sign: closed, or still open with the precise residual primitive.
Process
A controlled offensive loop
The process is designed to produce decisions: what happened, why it mattered, and exactly what needs to change.
Scope
Define authorization, assets, objectives, safety limits, and communication rules.
Emulate
Operate against the routes a real adversary would prefer, with measured pressure.
Prove
Validate exploitability and impact with clean artifacts, timelines, and reproduction.
Harden
Support remediation, retest critical paths, and leave the team with usable evidence.
Coordinated disclosure
Research ledger
Every vulnerability is reported to the vendor first and published only after coordinated disclosure.
| Identifier | Product | CVSS | Severity | Published | Status |
|---|---|---|---|---|---|
| CVE pending | Telegram Desktop (tdesktop) | 8.2 | High | 2026-09-12 | Fixed |
| CVE-2026-65494 | Dokan Pro (WordPress) | 7.1 | High | 2026-08-13 | Coordinated |
| CVE-2026-65493 | Dokan Pro (WordPress) | 7.5 | High | 2026-08-13 | Coordinated |
| CVE-2026-54825 | wpDataTables Premium (WordPress) | 9.3 | Critical | 2026-08-13 | Fixed |
| CVE-2026-54682 | DiscordChatExporter | 8.2 | High | 2026-08-13 | Fixed |
| CVE-2026-54681 | DiscordChatExporter | 4.1 | Medium | 2026-08-13 | Fixed |
| CVE-2026-17543 | PHP ext/pgsql (php-src) | 9.8 | Critical | 2026-06-02 | Fixed |
Engagements
Bring the systems that need real scrutiny.
Red team, exploit development, or focused vulnerability research for software and environments you own or are authorized to test.
// secure channel — PGP on request