Uploaded December 2025 | Updated September 2026, 1 week ago
CVEs are everywhere nowadays, with more and more exploitable CVEs appearing in the wild, flooding security teams with high-risk alerts. It's practically impossible for security engineers to try and focus their energy on fixing, triaging, and remediating all of them, which raises the question: Should we fix 'em all?
We fully analyzed multiple CVEs to give you in-depth and concrete examples for widely used exploitation techniques such as use-after-free, heap buffer overflow, and privilege escalation, and how even the most advanced techniques on a vulnerable kernel version could be irrelevant when outside the original exploit context.
We'll cover how known exploitable in the wild (KEV) CVEs found on one system cross to another, just to appear critical somewhere that it won’t be exploitable anymore. Shared kernel, shared libraries, shared patches, but ends up in a totally different environment. When irrelevant issues and relevant issues are treated the same, we lose our ability to move quickly and protect our cloud containers.
We’ll explore how we find the origin of the exploit, analyze the patch, and the patched code reachability, and the patched code execution path. Then we’ll dive into creating attack path scenarios, which help us find out if these CVEs are really exploitable inside their new context.
So what should defenders do? We’ll show how adding context, attack path simulations, and having an active remediation strategy can shorten triage time and reduce handling issues that are practically irrelevant. We’ll give you the tools and the right techniques to fix only the issues that really matter, and the right strategies for how to build a solid and contextualized foundation for your cloud container security.
Liad Cohen
OX Security
Security Research Team Lead
Liad Cohen is a Security Research Team Lead and a Data Scientist at OX Security. His day-to-day work involves empowering open source security and code security with AI capabilities, developing innovative data-driven AppSec detection systems from ideation to PoCs to production, and making product roadmap a reality, backed by deep pioneer security research. He started his career as a young "script kiddie", later becoming a gifted mathematician. Liad holds a Master of Science degree in Computer Science. He is a Mentor in hackathons and CTFs, publishing academic papers and articles in security journals and presented state of the art security research at BlackHat USA, RSA Conference, OWASP Global and others.
linkedin.com/in/securing
ox.security (company)
Moshe Siman Tov Bustan
OX Security
Security Researcher
Moshe is a Senior Security Researcher at OX Security, a company specializing in software supply chain security, and has worked in the security industry for 13 years. His work spans cloud security research, container security, memory forensics, and an in-depth understanding of programming languages. He also has extensive experience in mobile security, including iOS and Android research, deep analysis of Android malware, sandboxing, and memory forensics.
Beyond security research, Moshe has published multiple "Can It Run Doom?" projects online, and is also a professional guitarist in a progressive metal band.
linkedin.com/in/hexploit
Managed by the OWASP® Foundation
owasp.org
CVEs are everywhere nowadays, with more and more exploitable CVEs appearing in the wild, flooding security teams with high-risk alerts. It's practically impossible for security engineers to try and focus their energy on fixing, triaging, and remediating all of them, which raises the question: Should we fix 'em all?
We fully analyzed multiple CVEs to give you in-depth and concrete examples for widely used exploitation techniques such as use-after-free, heap buffer overflow, and privilege escalation, and how even the most advanced techniques on a vulnerable kernel version could be irrelevant when outside the original exploit context.
We'll cover how known exploitable in the wild (KEV) CVEs found on one system cross to another, just to appear critical somewhere that it won’t be exploitable anymore. Shared kernel, shared libraries, shared patches, but ends up in a totally different environment. When irrelevant issues and relevant issues are treated the same, we lose our ability to move quickly and protect our cloud containers.
We’ll explore how we find the origin of the exploit, analyze the patch, and the patched code reachability, and the patched code execution path. Then we’ll dive into creating attack path scenarios, which help us find out if these CVEs are really exploitable inside their new context.
So what should defenders do? We’ll show how adding context, attack path simulations, and having an active remediation strategy can shorten triage time and reduce handling issues that are practically irrelevant. We’ll give you the tools and the right techniques to fix only the issues that really matter, and the right strategies for how to build a solid and contextualized foundation for your cloud container security.
Liad Cohen
OX Security
Security Research Team Lead
Liad Cohen is a Security Research Team Lead and a Data Scientist at OX Security. His day-to-day work involves empowering open source security and code security with AI capabilities, developing innovative data-driven AppSec detection systems from ideation to PoCs to production, and making product roadmap a reality, backed by deep pioneer security research. He started his career as a young "script kiddie", later becoming a gifted mathematician. Liad holds a Master of Science degree in Computer Science. He is a Mentor in hackathons and CTFs, publishing academic papers and articles in security journals and presented state of the art security research at BlackHat USA, RSA Conference, OWASP Global and others.
linkedin.com/in/securing
ox.security (company)
Moshe Siman Tov Bustan
OX Security
Security Researcher
Moshe is a Senior Security Researcher at OX Security, a company specializing in software supply chain security, and has worked in the security industry for 13 years. His work spans cloud security research, container security, memory forensics, and an in-depth understanding of programming languages. He also has extensive experience in mobile security, including iOS and Android research, deep analysis of Android malware, sandboxing, and memory forensics.
Beyond security research, Moshe has published multiple "Can It Run Doom?" projects online, and is also a professional guitarist in a progressive metal band.
linkedin.com/in/hexploit
Managed by the OWASP® Foundation
owasp.org










