VULNARY
Verdict · The proving engine

Any vulnerability.Proven.

A CVE, a finding, a hunch. Verdict reconstructs it from source or binary into a live, working exploit in an isolated lab — then writes the fix. Risk scores start arguments; a working exploit ends them.

Every exploit built + verified against an isolated, dedicated instance · coordinated-disclosure norms

We don't rate risk — we prove it. Verdict either lands a working exploit, or it marks the finding noise. No maybes, no inflated severities, no theatre.
01 · HOW IT WORKS

Disclosure to exploit, unattended.

RECONSTRUCT

Stand the target up, exactly

Verdict builds the vulnerable target in an isolated lab — the right version, the right config, the surface the bug actually needs — from source or binary.

isolated
dedicated
REASON

Find the path that lands

It studies the code and the running system, forms the attack, and drives toward a real primitive — not a signature match, the actual reachable condition.

reachable
or noise
EXPLOIT

Make it actually fire

It builds and runs the exploit against the live instance until the effect is real and repeatable — a shell, a read, a controlled crash.

live
repeatable
VERIFY & FIX

Prove it, then close it

Every claim is backed by a reproducible trace, and Verdict emits the fix that ends it. A verdict you can hand to engineering, your board, or an auditor.

signed
+ the fix
02 · THE RECORD
Different languages, different bug classes — up to a heap overflow in nginx that only an AddressSanitizer build could even see. The same outcome every time: a working exploit, not a maybe.

Each entry the Resident reconstructed on its own, from a published CVE to a live, verified exploit, unattended. Hand Verdict any vulnerability — public or private, ours or not — and it gives you the exploit that proves it lands.

CVE-2026-42945nginx · heap overflow (C)PROVEN
CVE-2026-34197ActiveMQ · Jolokia→xbeanPROVEN
CVE-2026-48907Joomla JCE · unrestricted uploadPROVEN
CVE-2025-24893XWiki · unauth SSTI→RCEPROVEN

Hand us a vulnerability. Get the exploit.

Book a demo and watch Verdict reconstruct a real one end to end — exploit, proof, and the fix that closes it.

Book a demo →