# offensive security · bug bounty · ctf
PNDSEC started as one researcher's bug-bounty handle. It's growing into a small team — web & mobile penetration testing, CTF, and open-source tooling for people who like taking things apart.
| cve | vendor / product | added |
|---|---|---|
| CVE-2026-93952 | Arista / VeloCloud Orchestrator | 2026-09-22 |
| CVE-2026-94127 | F5 / BIG-IP APM | 2026-09-22 |
| CVE-2026-93616 | Check Point / Multiple Products | 2026-09-22 |
| CVE-2026-85102 | Check Point / Multiple Products | 2026-09-22 |
| CVE-2026-7273 | Zyxel / GS1900 Series Switches | 2026-09-21 |
1721 actively exploited CVEs tracked by CISA — full catalog