Prospective clients reasonably want to know whether a security consultancy finds real defects in real software, and the honest answer to that question is a list of advisories with someone else’s name on the fix. This post is that list, kept in one place and updated as new advisories become public.
Everything below is public. Nothing on this page is under embargo, and each row links to the vendor or coordinator advisory so the claim can be checked independently rather than taken on our word.
Published CVEs
| CVE | Affected product | Impact | CVSS v3 | Advisory |
|---|---|---|---|---|
| CVE-2026-53752 | docx4j (Java OpenXML library) | Uncontrolled recursion on cyclic style chains causes stack exhaustion and denial of service | 7.5 High | GHSA-gc95-3vw8-vg43 |
| CVE-2024-44807 | D-ZERO BurgerEditor for baserCMS | Directory listing exposes uploaded files to remote users | 5.3 Medium | JVN#54676967 |
| CVE-2022-46330 | Squirrel.Windows installers | Insecure DLL search path allows code execution as the invoking user | 7.8 High | JVN#29902403 |
| CVE-2021-33897 | Synthesia | Buffer overflow on malformed MIDI under non-Latin locales causes persistent crash | 5.5 Medium | NVD |
| CVE-2021-4144 | TP-Link TL-WR802N V4 (JP) | OS command injection in the router web interface | 8.8 High | JVNVU#94883311 |
| CVE-2020-35576 | TP-Link TL-WR841N V13 (JP) | Command injection in the traceroute feature yields arbitrary code execution as root | 8.8 High | JVNVU#92444096 |
| CVE-2020-25900 | HelloTalk | Full-precision GPS coordinates retained and replicated to other users’ devices despite coarse sharing settings | 5.3 Medium | NVD |
Two of these were coordinated through JPCERT/CC and IPA under the Japanese vulnerability handling framework, which is a slower process than a bug bounty triage queue and a considerably more rigorous one. Both TP-Link findings resulted in firmware updates for the affected JP-market models.
Vendor acknowledgements without public technical detail
ONLYOFFICE named Isopach on its corporate blog in July 2026, thanking “isopach (is-)” for “submitting numerous reports via the platform” through its HackerOne programme. The individual reports remain under that programme’s disclosure terms, so we can confirm the credit and not the contents. There is a fuller note on this in our post about the acknowledgement.
A note on attribution
Isopach Pte Ltd was incorporated in 2022, but the Isopach name has covered this research since 2017. Several of the older advisories were reported under prior employment, and the coordinator records name the employer of record at the time rather than Isopach; the BurgerEditor advisory is additionally shared with a co-reporter. The linked JVN entries carry the full attribution in each case. They are listed here because they form one continuous body of work under the Isopach name, not to suggest the company performed engagements that predate it.
What this means for an engagement
The through-line across these advisories is that they are all defects that survived the vendor’s own testing and, in most cases, a scanner pass. Command injection reachable from an authenticated router interface, a DLL search-path flaw in an installer framework that thousands of desktop applications embed, a privacy control applied only in the view layer, and a parser that trusts a document to be acyclic are not findings that a tool reports. They come from reading the implementation and asking what assumption is holding it together.
That is the same approach we bring to client work. If you would like to discuss an assessment, get in touch.