300+ vulnerabilities reported since 2022

Muneeb Amin Bhat’s research, from an Oracle CVE in 2022 to the company he opened in August 2026.

Halls of fame and bounties

Web3: audits and rewards

  • VeChainThor
  • Multipli Smart Contracts
  • Internet Computer Protocol (ICP)
  • Snowbridge On-Chain Code
  • Olas
  • Injective Peggy Bridge

Where I hunt

Deep in the stack or out on the open web, the job is the same: find what breaks, prove it, report it.

  1. Operating-system kernels

    The core of the operating system. A bug there reaches everything above it.

    • Apple CVE-2026-43816
  2. Enterprise software

    Business suites that hold a company’s money, staff and data.

    • Oracle E-Business Suite CVE-2022-21500
    • Zendesk
    • Asana
  3. Secure firmware

    Code that runs before the operating system, where trust starts.

    • Arm Trusted Firmware Accepted and rewarded
  4. Web and cloud

    Servers, APIs and the cloud behind them.

    • Apple web servers 2023
    • NASA VDP Hall of Fame 2024
  5. Finance and fintech

    Banks, exchanges and payments, where a bug touches real money.

    • USAA
    • Kraken
    • Binance
    • Fireblocks
    • Lightspark
  6. Web3 and smart contracts

    Chains, bridges and the contracts on them, where the code is the vault.

    • VeChainThor
    • Multipli Smart Contracts
    • Internet Computer Protocol (ICP)
    • Snowbridge On-Chain Code
    • Olas
    • Injective Peggy Bridge
  7. AI

    New systems, and new ways for them to fail.

    • Anthropic
  8. Open source and self-hosted

    Code anyone can read, run by people on their own servers.

    • FFmpeg
    • Nextcloud
  9. Consumer platforms

    The apps people open every day.

    • Google
    • Indeed
    • Pinterest
    • McDonald’s

Year by year

  1. First reports

    Starts hunting on bug bounty and disclosure programs.

  2. CVE-2022-21500, credited by Oracle

    Oracle E-Business Suite. CVSS 3.1 base score 7.5.

    Sourcefor CVE-2022-21500, credited by Oracle (opens in a new tab)
  3. Apple Web Server Security Acknowledgements

    Listed for reports on Apple’s web servers.

    Sourcefor Apple Web Server Security Acknowledgements (opens in a new tab)
  4. First press, at home

    Daily Excelsior, Kashmir Life and Greater Kashmir cover the Apple listing.

    Sourcefor First press, at home (opens in a new tab)
  5. NASA VDP Hall of Fame

  6. WION, on prime time

    WION runs the NASA story online and on Gravitas. ANI, DNA India and ABP Live follow.

    Sourcefor WION, on prime time (opens in a new tab)
  7. The Hindu BusinessLine feature

    His reports to Apple, NASA and Google, online and in print.

    Sourcefor The Hindu BusinessLine feature (opens in a new tab)
  8. NITI Aayog Frontier Tech Hub

    Profiled in “Guardians of the Grid”.

    Sourcefor NITI Aayog Frontier Tech Hub (opens in a new tab)
  9. Firmware findings rewarded by Arm

    Accepted and rewarded in the Trusted Firmware scope.

  10. CVE-2026-43816, credited by Apple

    A kernel out-of-bounds write, fixed in iOS 26.6 and macOS Tahoe 26.6.

    Sourcefor CVE-2026-43816, credited by Apple (opens in a new tab)
  11. Vulnara Technologies opens

    MSME registered, Udyam UDYAM-JK-11-0024606.

  12. 300+vulnerabilities reported

    The count as of September 2026, since 2022.

CVEs with his name on them

Oracle E-Business Suite May 2022

CVE-2022-21500

CVSS 3.1 base score 7.5, from Oracle’s own Security Alert. The alert credits him as “Bhat Muneeb”.

Oracle Security Alert(opens in a new tab)

Inside Arm’s Trusted Firmware

In 2026 Arm’s bug bounty program accepted and rewarded his findings in its Trusted Firmware scope.

Firmware and IoT testing

Listed and thanked

  • NASA

    Vulnerability Disclosure Program Hall of FameHall of fame

    2024

  • Indeed

    Hall of Fame

  • USAA

    Hall of Fame

  • Acronis

    Bug bounty programAcknowledgement

  • Anthropic

    Security programAcknowledgement

  • Lightspark

    Bug bounty programAcknowledgement

Stories behind the record

  1. Arm and Apple

    Down to the kernel

    In 2026 Arm’s bug bounty program accepted and rewarded my findings in Trusted Firmware. In July Apple credited me for CVE-2026-43816, a kernel out-of-bounds write. A month later I opened Vulnara.

From Kashmir to the world

I work from Kulgam, in south Kashmir. My reports land with security teams in the US, the UK and Germany.

  • KulgamtoUnited States

    Apple, Google, NASA, NVIDIA, USAA, Indeed, Kraken, Vercel, Lightspark, Anthropic, Oracle, McDonald’s, Pinterest, Zendesk, Asana and Fireblocks

  • KulgamtoUnited Kingdom

    Arm

  • KulgamtoGermany

    SimScale and Nextcloud

  • KulgamtoIndia

    NITI Aayog

Profiled by NITI Aayog

In 2025 the Government of India’s policy think tank put him in a Frontier Tech Hub story on young Indians in cyber security.

Guardians of the Grid: 7 Young Indians Fortifying Our Cyber Frontiers

NITI Aayog Frontier Tech Hub, 2025Read the story(opens in a new tab)
Headlines from the press: read the coverage

In the press

All coverage

Tell us what to break. Or what to build.

Send the scope and your deadline, and we’ll set up a call.