Skip to content
You can now search across every topic, entity and event.What's new
WatchTowr Labs
OrganisationSG

WatchTowr Labs

Offensive-security research firm known for fast public proof-of-concept exploits of enterprise flaws.

Last refreshed: 24 June 2026 · Appears in 1 active topic

Key Question

Which firm published the Splunk proof-of-concept that forced the first-ever Splunk KEV entry?

Timeline for WatchTowr Labs

#8 18 Jun

Splunk lands its first-ever KEV entry

Cybersecurity: Threats and Defences
#7 8 Jun

Published working PoC and identified CWE-1337 root cause in Check Point IKEv1 handshake

Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patch
#3 30 Apr

Disclosed CVE-2026-41940 and provided exploitation telemetry

Cybersecurity: Threats and Defences: cPanel zero-day ran 65 days before patch; Sorry ransomware active
#1 23 Mar

Detected active reconnaissance of CVE-2026-3055 in the wild

Cybersecurity: Threats and Defences: CitrixBleed 3 lands on SAML broker
View full timeline →

Background

WatchTowr Labs is a Singapore-based offensive-security research and attack-surface management firm founded in 2022. Its research division scans internet-facing enterprise infrastructure proactively and publishes exploitation telemetry and proof-of-concept code on high-severity vulnerabilities, typically ahead of or concurrent with CISA KEV catalogue additions and national CERT advisories. UK NCSC and Five Eyes partners regularly cite WatchTowr pre-patch exploitation data in their own advisories. In March 2026 WatchTowr confirmed active reconnaissance in the wild against CVE-2026-3055 (CitrixBleed 3, CVSS v4.0 9.3), providing the primary early-warning data cited by CISA when it added the flaw to the KEV catalogue on 28 March with a 2 April federal deadline.

In April 2026 WatchTowr Labs disclosed CVE-2026-41940, a CVSS 9.8 CRLF-injection in the cPanel cpsrvd login daemon allowing unauthenticated session hijacking to root. The flaw had run as a true zero-day for 65 days before WebPros patched it on 28 April 2026; KnownHost telemetry confirmed active exploitation dating to 23 February, with 'Sorry' ransomware deploying a Go-language Linux encryptor throughout the window. CISA added it to KEV on 30 April. In June 2026 WatchTowr published the root-cause analysis and working proof-of-concept for the Check Point Remote Access VPN zero-day CVE-2026-50751 (CVSS 9.3), identifying CWE-1337 as the underlying design flaw; the vulnerability had been actively exploited for approximately one month before its hotfix shipped.

In June 2026 WatchTowr Labs published a working exploit for CVE-2026-20253, an unauthenticated missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar service, chaining it into a pre-authentication RCE chain. CISA added the flaw to KEV on 18 June with a 21 June federal Deadline, the first-ever Splunk KEV entry; Splunk confirmed active exploitation the same day. WatchTowr's business model combines a commercial attack-surface monitoring platform with public vulnerability research. Its consistent appearance in CISA and NCSC advisories as the source of pre-patch exploitation telemetry positions it as one of the more operationally relevant independent research firms on the perimeter-device and enterprise-software threat surface. It competes with Bishop Fox, NCC Group, and Assetnote in the offensive-research segment, with a distinct Asia-Pacific geographic coverage footprint.

Common Questions
What is WatchTowr Labs?
WatchTowr Labs is a Singapore-based offensive-security research firm founded in 2022. It publishes proof-of-concept exploits and exploitation telemetry on high-severity enterprise vulnerabilities, often ahead of CISA KEV additions. Its disclosures on Splunk, cPanel, CitrixBleed, and Check Point VPN have been cited by CISA and NCSC.Source: WatchTowr official description
What did WatchTowr find in Splunk Enterprise?
WatchTowr Labs published a working exploit for CVE-2026-20253, an unauthenticated file-write flaw in Splunk Enterprise's PostgreSQL sidecar, and chained it into a pre-authentication RCE. The exploit was public before CISA added the flaw to KEV on 18 June 2026 with a 21 June Deadline.Source: WatchTowr Labs Splunk disclosure, June 2026
Why does WatchTowr publish working exploits publicly?
WatchTowr's public vulnerability research serves dual purposes: it demonstrates the firm's offensive-research depth to prospective clients for its commercial attack-surface monitoring platform, and it provides a genuine early-warning layer for defenders by quantifying real exploitation before formal government advisories are issued.Source: WatchTowr research methodology
What other vulnerabilities has WatchTowr discovered?
WatchTowr confirmed active CitrixBleed 3 reconnaissance ahead of mass exploitation; disclosed a 65-day cPanel zero-day (CVE-2026-41940, CVSS 9.8) enabling unauthenticated root hijack; contributed early data on the Check Point VPN zero-day that ran open for a month before patch; and published the Splunk Enterprise pre-auth RCE chain in June 2026.Source: WatchTowr Labs public disclosures across cyber-threats-and-defences updates
What is WatchTowr Labs and what does it do?
WatchTowr Labs is a Singapore-based offensive-security research and attack-surface monitoring firm founded in 2022. It scans internet-facing enterprise infrastructure and publishes exploitation telemetry and proof-of-concept code ahead of or alongside CISA KEV additions, making it a primary early-warning source for CISA, NCSC, and enterprise security teams.Source: event
Did WatchTowr Labs find the Splunk vulnerability that got KEV-listed in June 2026?
Yes. WatchTowr Labs published a working pre-authentication RCE chain for CVE-2026-20253, a missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar. CISA listed it on 18 June 2026 with a three-day federal Deadline, the first-ever Splunk KEV entry.Source: event
What was the cPanel zero-day that WatchTowr disclosed in 2026?
WatchTowr Labs disclosed CVE-2026-41940, a CVSS 9.8 CRLF-injection in cPanel's login daemon (cpsrvd) that allowed unauthenticated session hijacking to root. It had been actively exploited as a true zero-day for 65 days before the patch shipped on 28 April 2026, with 'Sorry' ransomware deployed on compromised hosts.Source: event
How does WatchTowr Labs get cited by CISA and NCSC?
WatchTowr Labs publishes exploitation telemetry and proof-of-concept code shortly before or concurrent with CISA KEV catalogue additions. Its pre-patch reconnaissance data on CitrixBleed 3, the cPanel zero-day, the Check Point VPN flaw, and the Splunk RCE has been cited as primary evidence in CISA and UK NCSC advisories.Source: event
What is CitrixBleed 3 and what did WatchTowr find?
CitrixBleed 3 (CVE-2026-3055) is a CVSS 9.3 unauthenticated memory overread in Citrix NetScaler when configured as a SAML identity provider, disclosed March 2026. WatchTowr Labs detected active reconnaissance in the wild before mass exploitation, providing the primary early-warning data cited by CISA when it added the flaw to KEV on 28 March 2026.Source: event
Source Material