[ Research ]

Research that survives real-world validation.

RootXLabs points its research at real production software. This page is the honest state of that work: the numbers and the published advisories are verifiable today; most of the rest is still under coordinated disclosure.

5
CVEs assigned
8
Vendors acknowledged
#700
Bugcrowd global rank
2022
Hunting since

Advisories

Findings confirmed by the vendor. Published records link to NVD; work still under coordinated disclosure appears here only once a fix ships.

MicrosoftPowerShell
CVE-2026-58612Information disclosureCVSS 7.4
Published · credited
MicrosoftPowerShell
CVE-2026-40400Remote code executionCVSS 7.8
Published · acknowledged
AXIS CommunicationsCamera Station
CVE-2026-63283Details withheldHigh
Published · details withheld
AppleWebKit
CVE-2026-64778Information disclosureCVSS 6.5
Published · credited
MicrosoftPowerShell
CVE-2026-70337Remote code executionCVSS 8.8
Published · acknowledged

Findings acknowledged by

  • Google
  • Apple
  • Meta
  • Microsoft
  • Cisco
  • Perplexity
  • Dell
  • NASA

Acknowledgement means the vendor independently reproduced the finding and credited it. It is the weakest claim we can make that is still worth anything — and unlike a severity rating, it is not ours to award.

Why the list stops there

Because most of our findings are not fixed yet. Naming a vendor alongside a product and a bug class is a disclosure whether or not a CVE ID is attached to it — anyone reading that pairing knows where to look, and the systems they would be looking at are still running the vulnerable version.

So this page carries counts, vendor names and the advisories that are already public — and nothing that maps an embargoed finding to a product. It is a weaker page than it could be. It is also the only version we can publish without handing someone a starting point.

If you are evaluating us and need more than a number, we will walk through the work under NDA — security@rootxlabs.ai.

How we disclose

The vendor hears first
Every finding goes to the vendor's security channel before it goes anywhere else — no pre-announcement, no teaser, no conference abstract that names the product.
The vendor sets the clock
We do not publish a fixed countdown. A complex fix takes longer than a simple one, and a deadline that forces a rushed patch helps nobody. We ask for a date and we hold to it.
Nothing that helps reach an unfixed system
Between report and fix we will confirm a finding exists if asked directly, and say nothing more — not the product name, the version range, or the bug class.
The write-up comes after the fix
Once a fix ships and the vendor is ready, the full analysis is published — the path we took, what the guard missed, and the proof-of-concept.

The full policy, including how to report something to us, is on /responsible-disclosure.

What we can show you: the method

The findings are embargoed. The way they are produced is not, and it is the part that generalises anyway.