All systems operationalSystems operational
Swiss Cloud Düdingen · 99.995% SLAMon to Fri 08:30 to 17:30+41 21 552 03 25
Home / Security Research
Security Research

Vulnerability research by our security team.

Our researchers discover 0-day vulnerabilities in the products of the world's largest software and hardware vendors, SonicWall, VMware, Sophos, Novell, Apple, Mitel, OPNsense, WatchGuard, validated by the Zero Day Initiative and published in the global CVE registry.

Vulnerability research and offensive security at DigitalCanion

Beyond client audits, our research team hunts for previously unknown (0-day) vulnerabilities in the products of the world's largest software and hardware vendors, then reports them under coordinated disclosure.

15published findings
50-day advisories
11referenced CVEs
8vendors
Filter
MitelMiVoice Office 4000-day

Mitel is the market leader in unified communications. Mitel MiVoice Office 400 to version R7.2 SP1, running Linux Release 11.0.96.0, does not implement Secure Boot, UEFI Secure Boot, boot/filesystem integrity protection, or LUKS disk encryption.

A malicious person or an attacker with access to the VMDK could therefore modify the virtual disk offline and inject persistent malicious code without being detected. Such code could execute automatically at system startup or when specific application features are triggered, allowing persistence across reboots, since there's no integrity check on system files. This exposes the solution to offline disk tampering, persistent code injection, boot-chain compromise, and lack of integrity verification. The absence of these controls significantly weakens the appliance's trust model and protection against persistent compromise.

Read the full advisory →
OPNsenseMultiple XSS (GHSA-9h93-hhcx-957c)CVE pending

DigitalCanion SA, through its researcher Brian Mariani (call-AX), identified multiple cross-site scripting (XSS) vulnerabilities in OPNsense 26.7.1_1, responsibly disclosed and published by the vendor in its GitHub security advisory (GHSA-9h93-hhcx-957c, 12 August 2026). The first is a stored XSS (Description field under Interfaces → Assignments): an attacker can inject JavaScript that executes for any user viewing the interface configuration, including root accounts. The second is a reflected XSS in Firewall → Log Files → Live View. Weaknesses: CWE-79 (Cross-site Scripting) and CWE-116 (improper output encoding/escaping). Severity: Low. A CVE identifier will soon be assigned via OPNsense; this page will be updated once it is published.

WatchGuardDGI-SWISS-00024Upcoming

DigitalCanion SA, through its researcher Brian Mariani, identified a high-severity vulnerability in a WatchGuard product, rated CVSS 7.3 (High). Referenced as DGI-SWISS-00024, it was reported to the vendor on September 1, 2026 and is undergoing coordinated disclosure, with publication planned for October 5, 2027. Technical details and the CVE identifier will be published once the embargo period ends; this page will be updated upon release.

SonicWallZDI-CAN-289240-day

DigitalCanion SA identified a security vulnerability affecting SonicWall products and responsibly disclosed it through the Zero Day Initiative (ZDI). The vulnerability was assigned the identifier ZDI-CAN-28924 and was rated CVSS 7.2 (High). The issue was reported on July 21, 2026, and coordinated through ZDI's responsible disclosure process; public disclosure scheduled for November 18, 2026. This discovery reflects DigitalCanion's ongoing commitment to proactive security research and responsible vulnerability disclosure.

SonicWallZDI-CAN-29029 · CVE-2026-66150Published CVE

DigitalCanion SA, through its researcher Brian Mariani, identified a command injection vulnerability in SonicWall Email Security (ES 5000/5050/7000/7050/9000 appliances, VMware and Hyper-V), version 10.0.35.8405 and earlier. An authenticated attacker with access to the restricted CLI can inject OS commands executed as root via the SNMP parameter. Reported on April 16, 2026 and coordinated through the Zero Day Initiative (ZDI-CAN-29029), it was published on August 11, 2026 as CVE-2026-66150 (CVSS 7.8, High) in ZDI advisory ZDI-26-530 and SonicWall advisory SNWLID-2026-0012. Fixed in Email Security 10.0.36.

SonicWallZDI-CAN-290240-day

DigitalCanion SA identified a security vulnerability affecting SonicWall products and responsibly disclosed it through the Zero Day Initiative (ZDI). The vulnerability was assigned the identifier ZDI-CAN-29024 and was rated CVSS 7.8 (High). The issue was reported on April 16, 2026, and coordinated through ZDI's responsible disclosure process. It is now published as CVE-2026-66148 in SonicWall advisory SNWLID-2026-0011 and ZDI advisory ZDI-26-531. This discovery reflects DigitalCanion's ongoing commitment to proactive security research and responsible vulnerability disclosure.

SonicWallZDI-CAN-29025 · CVE-2026-66149Published CVE

DigitalCanion SA, through its researcher Brian Mariani, identified a command injection vulnerability in SonicWall Email Security (ES 5000/5050/7000/7050/9000 appliances, VMware and Hyper-V), version 10.0.35.8405 and earlier. An authenticated attacker with access to the restricted CLI can inject OS commands executed as root via the netmask (updateNetIf) parameter. Reported on April 16, 2026 and coordinated through the Zero Day Initiative (ZDI-CAN-29025), it was published on August 11, 2026 as CVE-2026-66149 (CVSS 7.8, High) in ZDI advisory ZDI-26-532 and SonicWall advisory SNWLID-2026-0012. Fixed in Email Security 10.0.36.

SonicWallCVE-2026-66148 & CVE-2026-66146 · SonicWall GMS2 published CVEs

Two vulnerabilities discovered and disclosed by DigitalCanion SA in SonicWall GMS 9.5.1 and earlier versions. CVE-2026-66148 (CVSS 6.3): an authenticated command injection allowing a low-privileged local user to execute system commands with root privileges, originally coordinated through the Zero Day Initiative (ZDI-CAN-29024). CVE-2026-66146 (CVSS 5.5): multiple Cross-Site Scripting (XSS) vulnerabilities allowing execution of JavaScript in a user's browser. Published in the official SonicWall advisory SNWLID-2026-0011 of August 11, 2026, and fixed by the vendor in GMS 9.5.2.

SonicWallCVE-2025-40604 & CVE-2025-406052 published CVEs

Two security vulnerabilities identified and disclosed in SonicWall products, reported through the appropriate channels and fixed by the vendor. An illustration of the importance of continuous security testing, transparency and responsible disclosure.

VMwareVulnerability in VMware 17.6 (Broadcom)Acknowledged

A vulnerability discovered in VMware 17.6. Although Broadcom acknowledged the issue, it stated it would only resolve it "in upcoming versions", with no clear timeline. A full technical report documents the finding.

SonicWallThree CVEs in SonicWall Email Security3 published CVEs

Three vulnerabilities identified in the SonicWall Email Security (antispam) solution that may put the email infrastructure at risk: CVE-2026-3468, CVE-2026-3469 and CVE-2026-3470. Prompt remediation is essential to reduce exposure of a critical messaging layer.

SonicWallCompromising SonicWall SSLVPN 10.2.2.2Demonstration

Multiple critical vulnerabilities affecting SonicWall SSL VPN. Although their exploitation requires read and write access to the machine's virtual disk, this demonstration illustrates how quickly a malicious insider, or an attacker who has obtained such access, can compromise the security of the SSL VPN system. Despite their impact, these design flaws were not fixed by SonicWall. This solution is now end-of-life and no longer maintained.

SophosPersistent exploit on Sophos SFOS 21.05.0.171Exploit chain

An attacker with R/W access to the VM's storage can tamper with system binaries. Modifying the SSH daemon injects an arbitrary shell, guaranteeing highly persistent remote access that survives reboots, despite deceptive integrity-validation messages. Furthermore, cleartext communication between the GUI and the backend enables theft of administrator credentials. Sophos declined to fix these design flaws; no patch is expected.

SophosAuthentication bypass on Sophos XGRCE + persistence

While this attack requires prior access to the virtual machine's disks, that constraint cannot justify the absence of adequate protection mechanisms. As it stands, the Sophos firewall solution shows significant shortcomings in reliability and resilience against unauthorized modifications of its files.

File integrity verification at startup is a fundamental security measure for this type of solution. Had an integrity-checking mechanism been implemented, any unauthorized modification would have been detected and corrected at the next reboot or update. The persistence of the attack would then have been limited to the interval before the system's next reboot or update.

We immediately reported this vulnerability to Sophos. However, the vendor declined to implement the security mechanisms needed to address this weakness.

NovellCVE-2014-0610 · Novell (bug 874533)Published CVE

A vulnerability affecting a Novell product (vendor-internal reference: bug 874533), published in the global registry as CVE-2014-0610. This research is part of the track record of Brian Mariani, now a cybersecurity expert at DigitalCanion SA. Full technical details are available in the reference entries below (Shodan, Tenable, VulDB, Debian, the CVE registry and NVD).

AppleCVE-2007-4707 · Apple QuickTime (Flash media handler)Published CVE

Vulnerability published by Apple in the QuickTime 7.3.1 security bulletin. This research is part of the track record of Brian Mariani (then a researcher at Syseclabs), now a cybersecurity expert at DigitalCanion SA.

CVE ID: CVE-2007-4707
Available for: Mac OS X v10.3.9, Mac OS X v10.4.9 or later, Mac OS X v10.5 or later, Windows Vista and Windows XP SP2.
Impact: QuickTime's Flash media handler contains multiple security vulnerabilities.

Description: Multiple vulnerabilities were identified in QuickTime's Flash media handler; the most serious could allow an attacker to execute arbitrary code on the computer. Apple addressed the issue by disabling the Flash media handler in QuickTime, except for a limited number of existing QuickTime movies considered safe. In its security bulletin, Apple credits Tom Ferris of the Adobe Secure Software Engineering Team (ASSET), Mike Price of McAfee Avert Labs, security researchers Lionel d'Hauenens and Brian Mariani of Syseclabs, and an anonymous researcher working with TippingPoint's Zero Day Initiative for reporting this issue.

Upcoming disclosures

Upcoming advisories

Vulnerabilities reported to vendors and undergoing coordinated disclosure, ahead of public CVE publication.

AdvisoryVendorCVSSStatusReportedPlanned disclosureResearcher
DGI-SWISS-00022Mitel9.1Upcoming2026-09-012027-10-05Brian Mariani
DGI-SWISS-00023Mitel7.1Upcoming2026-09-012027-10-05Brian Mariani
DGI-SWISS-00024WatchGuard7.3Upcoming2026-09-012027-10-05Brian Mariani

Zero Day Initiative : upcoming advisories → 🏆 SonicWall Hall of Fame →

Vulnerabilities credited to the research team of DigitalCanion SA or drawn from the personal track record of its researchers, validated by the Zero Day Initiative and published in official vendor advisories and the global CVE registry.

In the press

Our findings in the press and CVE databases

The vulnerabilities we disclose are published in the global CVE registry, credited to our team (Brian Mariani, DigitalCanion SA) and covered by specialised cybersecurity media.

Official CVE records & vendor advisories

Every published vulnerability is referenced in the global CVE registry (MITRE), the NIST NVD database and the vendor's official advisory, authoritative sources that credit our findings.

Let's talk about your project.

Over 12 years of Swiss expertise at your service. Reply within 24 business hours.

Contact us