Our public vulnerability disclosure record

A consolidated index of the CVEs and vendor acknowledgements published under the Isopach name since 2020, covering network equipment, desktop software, mobile applications, and open-source libraries.

Our public vulnerability disclosure record

Prospective clients reasonably want to know whether a security consultancy finds real defects in real software, and the honest answer to that question is a list of advisories with someone else’s name on the fix. This post is that list, kept in one place and updated as new advisories become public.

Everything below is public. Nothing on this page is under embargo, and each row links to the vendor or coordinator advisory so the claim can be checked independently rather than taken on our word.

Published CVEs

CVE Affected product Impact CVSS v3 Advisory
CVE-2026-53752 docx4j (Java OpenXML library) Uncontrolled recursion on cyclic style chains causes stack exhaustion and denial of service 7.5 High GHSA-gc95-3vw8-vg43
CVE-2024-44807 D-ZERO BurgerEditor for baserCMS Directory listing exposes uploaded files to remote users 5.3 Medium JVN#54676967
CVE-2022-46330 Squirrel.Windows installers Insecure DLL search path allows code execution as the invoking user 7.8 High JVN#29902403
CVE-2021-33897 Synthesia Buffer overflow on malformed MIDI under non-Latin locales causes persistent crash 5.5 Medium NVD
CVE-2021-4144 TP-Link TL-WR802N V4 (JP) OS command injection in the router web interface 8.8 High JVNVU#94883311
CVE-2020-35576 TP-Link TL-WR841N V13 (JP) Command injection in the traceroute feature yields arbitrary code execution as root 8.8 High JVNVU#92444096
CVE-2020-25900 HelloTalk Full-precision GPS coordinates retained and replicated to other users’ devices despite coarse sharing settings 5.3 Medium NVD

Two of these were coordinated through JPCERT/CC and IPA under the Japanese vulnerability handling framework, which is a slower process than a bug bounty triage queue and a considerably more rigorous one. Both TP-Link findings resulted in firmware updates for the affected JP-market models.

Vendor acknowledgements without public technical detail

ONLYOFFICE named Isopach on its corporate blog in July 2026, thanking “isopach (is-)” for “submitting numerous reports via the platform” through its HackerOne programme. The individual reports remain under that programme’s disclosure terms, so we can confirm the credit and not the contents. There is a fuller note on this in our post about the acknowledgement.

A note on attribution

Isopach Pte Ltd was incorporated in 2022, but the Isopach name has covered this research since 2017. Several of the older advisories were reported under prior employment, and the coordinator records name the employer of record at the time rather than Isopach; the BurgerEditor advisory is additionally shared with a co-reporter. The linked JVN entries carry the full attribution in each case. They are listed here because they form one continuous body of work under the Isopach name, not to suggest the company performed engagements that predate it.

What this means for an engagement

The through-line across these advisories is that they are all defects that survived the vendor’s own testing and, in most cases, a scanner pass. Command injection reachable from an authenticated router interface, a DLL search-path flaw in an installer framework that thousands of desktop applications embed, a privacy control applied only in the view layer, and a parser that trusts a document to be acyclic are not findings that a tool reports. They come from reading the implementation and asking what assumption is holding it together.

That is the same approach we bring to client work. If you would like to discuss an assessment, get in touch.

essential