A model can suggest where a vulnerability might be. Securin proves it, exploits it, reproduces it, and fixes it, under CNA and GNA authority.
117 advisories published · indexed since 2015
AI surfaces candidates at scale. Every candidate is reproduced by a practitioner before it counts as a finding, false positives, theoretical issues, and duplicates are discarded at this gate.
Counts a finding as a real vulnerability when a practitioner confirms it, including bugs later found to be already-reported or marked won't-fix. Shipped patches are the more reliable measure of impact.
Published entries link to the full advisory via the Securin reference. CVE IDs are assigned and indexed after the coordination window closes.
| SEC ZD · CVE | Vendor · Product | Vulnerability | CVSS | Status | Artifacts | |
|---|---|---|---|---|---|---|
sec-zd-421 CVE-2026-14191 | RARLAB WinRAR / RAR / UnRAR / UnRAR.dll | WinRAR/UnRAR RAR5 Recovery Volume (.rev) Out-of-Bounds Heap Write in RecVolumes5::ReadHeader Jul 1, 2026 | 7.8High | Fixed | - | Read |
sec-zd-378 CVE-2026-44041 | UltraVNC UltraVNC | vncWc2Mb wcslen Before Bounds Check (UltraVNC) Jun 3, 2026 | 4.3Medium | Fixed | - | Read |
sec-zd-377 CVE-2026-44042 | UltraVNC UltraVNC Repeater | wi_uudecode Boundary Off-by-One — Bounded (UltraVNC Repeater) Jun 3, 2026 | 3.7Low | Fixed | - | Read |
sec-zd-376 CVE-2026-7828 | UltraVNC UltraVNC Repeater | Integer Overflow in Repeater win_log malloc — Bounded (UltraVNC) Jun 3, 2026 | 5.3Medium | Fixed | - | Read |
sec-zd-375 CVE-2026-44040 | UltraVNC UltraVNC Server | libc rand() Used for VNC Auth Challenge Generation (UltraVNC) Jun 3, 2026 | 4.8Medium | Fixed | - | Read |
sec-zd-374 CVE-2026-7829 | UltraVNC UltraVNC Repeater | OOB NUL Write in Repeater Rule Parser (UltraVNC — post-auth) Jun 3, 2026 | 7.2High | Fixed | - | Read |
Counts as of August 2026 · 90-day coordinated disclosure window
AI accelerates coverage. Every output is validated by a practitioner before it counts.
Rules of engagement established upfront. Vulnerability intelligence focuses effort on targets that matter.
Frontier models map the attack surface at scale. Human expertise directs them to the code paths that matter.
Every output is triaged against practitioner tradecraft, discarding false positives, theoretical issues, and hallucinated findings. What remains is forged into working exploits and exploit chains.
Vendor receives the report and exploit under a 90-day embargo. We coordinate the patch and publish the full advisory under CNA and GNA authority.