lvl0x00, LLC delivers offensive and defensive cybersecurity services to federal, state, and local government agencies. We find the vulnerabilities before adversaries do.
Comprehensive security capabilities tailored for government agencies and the contractors that support them.
Network, web application, cloud, wireless, and social engineering assessments that simulate real-world attack scenarios against your infrastructure.
Full-scope adversary simulations that test your people, processes, and technology across the entire kill chain — from initial access to mission objectives.
Continuous scanning, prioritized remediation guidance, and ongoing program maturity assessments to reduce your agency's attack surface over time.
Rapid containment, digital forensics, root cause analysis, and recovery support. We help agencies prepare for, respond to, and recover from security incidents.
NIST 800-53, NIST CSF, FedRAMP, FISMA, CMMC, and StateRAMP assessment support. We guide agencies and contractors through the authorization lifecycle.
Secure-by-design architecture reviews, zero trust implementation strategy, and cloud security engineering for AWS GovCloud and Azure Government environments.
lvl0x00, LLC is a cybersecurity firm founded by practitioners with deep roots in offensive security and government operations. We work exclusively with public sector organizations — federal civilian agencies, the Department of Defense, state and local governments, and the contractors in their supply chains.
Our team brings hands-on experience in penetration testing, red team operations, vulnerability research, and security engineering. We understand the unique compliance requirements, threat landscapes, and operational constraints that government agencies face.
We are small by design. That means direct access to senior practitioners on every engagement — no bait-and-switch staffing, no layers of project management between you and the people doing the work.
We find vulnerabilities in the software agencies already run, then work the finding through coordinated disclosure until the vendor ships a fix. Every identifier below credits lvl0x00.
21 CVE IDs since 2023 · 8 rated critical · high of 10.0 · 5 vendors
| CVE | Product | Class | CVSS |
|---|---|---|---|
| Tenable12 | |||
| CVE-2026-19626 | Security Center | Eval InjectionCWE-95 | 9.9 |
| CVE-2026-18667 | Sensor Proxy | Code InjectionCWE-94 | 9.6 |
| CVE-2026-15265 | Agent | Path TraversalCWE-22 | 9.1 |
| CVE-2026-103947 | Nessus | Download Without Integrity CheckCWE-494 | 9.1 |
| CVE-2026-103946 | Nessus | SQL InjectionCWE-89 | 8.3 |
| CVE-2026-103951 | Nessus | Out-of-bounds WriteCWE-787 | 7.2 |
| CVE-2026-103950 | Nessus | Type ConfusionCWE-843 | 7.2 |
| CVE-2026-103948 | Nessus | Improper Length HandlingCWE-130 | 7.2 |
| CVE-2026-103955 | Nessus | Uncontrolled Resource ConsumptionCWE-400 | 4.9 |
| CVE-2026-103953 | Nessus | Use After FreeCWE-416 | 4.9 |
| CVE-2026-103952 | Nessus | Out-of-bounds WriteCWE-787 | 4.9 |
| CVE-2026-103954 | Nessus | Out-of-bounds ReadCWE-125 | 2.7 |
| NCEAS2 | |||
| CVE-2026-48114 | Metacat | SQL InjectionCWE-89 | 9.8 |
| CVE-2026-47754 | Metacat | Path TraversalCWE-22 | 9.3 |
| OPEXUS1 | |||
| CVE-2025-58462 | FOIAXpress Public Access Link | SQL InjectionCWE-89 | 9.8 |
| Iagona4 | |||
| CVE-2023-35189 | ScrutisWeb | Unrestricted File UploadCWE-434 | 10.0 |
| CVE-2023-33871 | ScrutisWeb | Path TraversalCWE-22 | 7.5 |
| CVE-2023-38257 | ScrutisWeb | Authorization BypassCWE-639 | 7.5 |
| CVE-2023-35763 | ScrutisWeb | Hard-coded CredentialsCWE-798 | 5.5 |
| Cesanta1 | |||
| CVE-2026-52054 | Mongoose | Infinite LoopCWE-835 | medium |
One further identifier is under coordinated disclosure, withheld until the vendor publishes: CVE-2026-19181 (Tenable Sensor Proxy).
Qualified, credentialed, and ready to support your agency's mission.
Team members hold active security clearances up to TS/SCI, enabling support for classified programs and environments.
Deep expertise in NIST security control frameworks, including assessment, implementation, and continuous monitoring.
Experience supporting cloud service providers through the FedRAMP and StateRAMP authorization process at all impact levels.
Our practitioners hold OSEE, OSCE, OSCP, GPEN, GXPN, CISSP, CISA, and other industry-recognized offensive and defensive certifications.
Tell us about your agency's security needs. All inquiries are confidential and we typically respond within one business day.
Your information will only be used to respond to your inquiry. We do not share contact information with third parties.