# offensive security · bug bounty · ctf
PNDSEC started as one researcher's bug-bounty handle. It's growing into a small team — web & mobile penetration testing, CTF, and open-source tooling for people who like taking things apart.
| cve | vendor / product | added |
|---|---|---|
| CVE-2026-84869 | ConnectWise / ScreenConnect | 2026-09-11 |
| CVE-2026-42016 | JFrog / Artifactory | 2026-09-11 |
| CVE-2026-42018 | JFrog / Artifactory | 2026-09-11 |
| CVE-2026-85706 | GitLab / Community Edition and Enterprise Edition | 2026-09-11 |
| CVE-2026-86060 | MikroTik / RouterOS | 2026-09-10 |
1709 actively exploited CVEs tracked by CISA — full catalog