Hi I'm Mehmet Ince - Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter Skip to content Posts CVE INDEX About Me X LinkedIn YouTube GitHub Hi I’m Mehmet Ince a hacker at heart, a builder by practice, and a mentor by purpose. As co-founder of PRODAFT, I’ve spent the last two decades in vulnerability research and security product engineering. Latests Blog Posts Jan 1, 2026 The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance It was May 2024, and our internal security team was evaluating the LogPoint SIEM/SOAR platform to replace our existing platform,… Read the story Dec 15, 2025 Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096) It was yet another day at the office. Our team was internally discussing moving to a different platform analytics solution.… Read the story Nov 7, 2025 The Chessboard of Security: Insights on Product Development and Vulnerabilities from a Hacker Perspective I was playing a quick game of chess while waiting for my coffee this morning. I had the white pieces… Read the story View all posts → Disclosed Vulnerabilities I’ve been in the vulnerability research field since 2004. Over the years, I’ve discovered and responsibly disclosed more than 300 vulnerabilities across a wide range of products and vendors. At this point, it’s almost impossible to keep track of all the CVE numbers I’ve accumulated — but I keep a personal index here. Latest disclosed CVEs: PostgreSQL Anonymizer CVE-2026-11945 | PostgreSQL Anonymizer: SQL injection in the rules import functions SQL Injection → CloudNative PostgreSQL CVE-2026-55769 | Overriding operators can lead to RCE Misconfiguration → CloudNative PostgreSQL CVE-2026-55765 | Cleartext role passwords recorded lead to RCE Misconfiguration → CloudNative PostgreSQL CVE-2026-44477 | Metrics exporter allows privilege escalation to RCE Misconfiguration → prompts.chat CVE-2026-22665 | Identity Confusion via Case-Sensitive Username Handling → View all Disclosed CVEs → Experience PRODAFT ◌ Chief Technology Officer Jan 2021 – Present ◌ VP, Threat Intelligence Products & Engineering Jan 2018 – Jan 2021 · 3 yrs ◌ Head of Offensive Security Jan 2016 – Jan 2018 · 2 yrs ◌ Principal Security Engineer & Platform Architect (Threat Intelligence) Jan 2013 – Jan 2015 · 2 yrs ◌ Lead Vulnerability Researcher & Security Software Engineer Jan 2012 – Jan 2015 · 3 yrs ◌ Co-Founder of PRODAFT Jan 2012 – Present SONY ◌ Senior Vulnerability Researcher Jan 2015 – Jan 2016 Private Security Consultant ◌ Linux and System Security Consultant Jan 2010 – Jan 2012 · 3 yrs Independent Vulnerability Researcher ◌ Discovered more than 300 vulnerabilities across a wide range of products and vendors. Jan 2008 – Present Talks TEDx | The Risk Brought by the Digital World: Cyber ​​Attacks TEDx | You Pressed Enter, Now You Can Sleep Github | Best way to RCE: Command Injection DEFCON AppSec Village | A Heaven for Hackers: Breaking Web Security NahamCon | A Heaven for Hackers: Breaking Web Security Virtual Appliance Hacktivity Breaking Log & SIEM Products Posts CVE INDEX About Me Search Search Close Previous Next