
WatchTowr Labs
Offensive-security research firm known for fast public proof-of-concept exploits of enterprise flaws.
Last refreshed: 24 June 2026 · Appears in 1 active topic
Which firm published the Splunk proof-of-concept that forced the first-ever Splunk KEV entry?
Timeline for WatchTowr Labs
Splunk lands its first-ever KEV entry
Cybersecurity: Threats and DefencesPublished working PoC and identified CWE-1337 root cause in Check Point IKEv1 handshake
Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patchDisclosed CVE-2026-41940 and provided exploitation telemetry
Cybersecurity: Threats and Defences: cPanel zero-day ran 65 days before patch; Sorry ransomware activeDetected active reconnaissance of CVE-2026-3055 in the wild
Cybersecurity: Threats and Defences: CitrixBleed 3 lands on SAML brokerBackground
WatchTowr Labs is a Singapore-based offensive-security research and attack-surface management firm founded in 2022. Its research division scans internet-facing enterprise infrastructure proactively and publishes exploitation telemetry and proof-of-concept code on high-severity vulnerabilities, typically ahead of or concurrent with CISA KEV catalogue additions and national CERT advisories. UK NCSC and Five Eyes partners regularly cite WatchTowr pre-patch exploitation data in their own advisories. In March 2026 WatchTowr confirmed active reconnaissance in the wild against CVE-2026-3055 (CitrixBleed 3, CVSS v4.0 9.3), providing the primary early-warning data cited by CISA when it added the flaw to the KEV catalogue on 28 March with a 2 April federal deadline.
In April 2026 WatchTowr Labs disclosed CVE-2026-41940, a CVSS 9.8 CRLF-injection in the cPanel cpsrvd login daemon allowing unauthenticated session hijacking to root. The flaw had run as a true zero-day for 65 days before WebPros patched it on 28 April 2026; KnownHost telemetry confirmed active exploitation dating to 23 February, with 'Sorry' ransomware deploying a Go-language Linux encryptor throughout the window. CISA added it to KEV on 30 April. In June 2026 WatchTowr published the root-cause analysis and working proof-of-concept for the Check Point Remote Access VPN zero-day CVE-2026-50751 (CVSS 9.3), identifying CWE-1337 as the underlying design flaw; the vulnerability had been actively exploited for approximately one month before its hotfix shipped.
In June 2026 WatchTowr Labs published a working exploit for CVE-2026-20253, an unauthenticated missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar service, chaining it into a pre-authentication RCE chain. CISA added the flaw to KEV on 18 June with a 21 June federal Deadline, the first-ever Splunk KEV entry; Splunk confirmed active exploitation the same day. WatchTowr's business model combines a commercial attack-surface monitoring platform with public vulnerability research. Its consistent appearance in CISA and NCSC advisories as the source of pre-patch exploitation telemetry positions it as one of the more operationally relevant independent research firms on the perimeter-device and enterprise-software threat surface. It competes with Bishop Fox, NCC Group, and Assetnote in the offensive-research segment, with a distinct Asia-Pacific geographic coverage footprint.