All systems operationalSystems operational
Swiss Cloud Düdingen · 99.995% SLAMon to Fri 08:30 to 17:30+41 21 552 03 25
Home / Security Research
Security Research

Vulnerability research by our security team.

Our researchers discover 0-day vulnerabilities in the products of the world's largest software and hardware vendors, SonicWall, VMware, Sophos, validated by the Zero Day Initiative and published in the global CVE registry.

Vulnerability research and offensive security at DigitalCanion

Beyond client audits, our research team hunts for previously unknown (0-day) vulnerabilities in the products of the world's largest software and hardware vendors, then reports them under coordinated disclosure. Our findings are validated by the Zero Day Initiative (ZDI), published in the global CVE registry and credited to DigitalCanion SA in official vendor advisories, offensive expertise that directly strengthens our clients' protection.

SonicWall VMware Sophos
SonicWall SSLVPN 3 × CVSS 7.8 · ZDI

Compromising SonicWall SSLVPN 10.2.2.2

Three critical vulnerabilities validated by the Zero Day Initiative (ZDI-CAN-29024, 29025, 29029). Our demonstration shows how swiftly a malicious insider, or an attacker with read/write access to the hypervisor, can compromise the security of the SSLVPN access system, a risk SonicWall refused to fix.

▶ Demonstration video
Sophos Firewall OS Exploit chain

Persistent exploit on Sophos SFOS 21.05.0.171

An attacker with R/W access to the VM's storage can tamper with system binaries. Modifying the SSH daemon injects an arbitrary shell, guaranteeing highly persistent remote access that survives reboots, despite deceptive integrity-validation messages. Furthermore, cleartext communication between the GUI and the backend enables theft of administrator credentials. Sophos declined to fix these design flaws; no patch is expected.

▶ Video 1 ▶ Video 2 ▶ Video 3
Sophos XG (SFOS 21.5) RCE + persistence

Authentication bypass on Sophos XG

Following a real cyberattack in which a company's firewall had been compromised to maintain persistence, our in-depth analysis of Sophos XG revealed several weaknesses, including an authentication bypass achieved by manipulating the virtual machine's memory snapshot, enabling arbitrary code execution and long-term persistence. Reported to Sophos, left unpatched after three weeks.

📄 Technical report
VMware 17.6 0-day

Vulnerability in VMware 17.6 (Broadcom)

A vulnerability discovered in the latest version of VMware 17.6, not yet fixed by the vendor. Although Broadcom acknowledged the issue, it stated it would only resolve it "in upcoming versions", with no clear timeline. A full technical report documents the finding.

📄 Technical report (Broadcom)
SonicWall Email Security 3 published CVEs

Three CVEs in SonicWall Email Security

Three vulnerabilities identified in the SonicWall Email Security (antispam) solution that may put the email infrastructure at risk: CVE-2026-3468, CVE-2026-3469 and CVE-2026-3470. Prompt remediation is essential to reduce exposure of a critical messaging layer.

🔗 Advisory SNWLID-2026-0002
SonicWall 2 published CVEs

CVE-2025-40604 & CVE-2025-40605

Two security vulnerabilities identified and disclosed in SonicWall products, reported through the appropriate channels and fixed by the vendor. An illustration of the importance of continuous security testing, transparency and responsible disclosure.

CVE-2025-40604 CVE-2025-40605 Advisory 2025-0018

Zero Day Initiative : upcoming advisories →    🏆 SonicWall Hall of Fame →

Vulnerabilities credited to the research team of DigitalCanion SA, validated by the Zero Day Initiative and published in official vendor advisories and the global CVE registry.

Let's talk about your project.

Over 12 years of Swiss expertise at your service. Reply within 24 business hours.

Contact us