Many closed doors can be kicked open by attackers willing to undergo offensive Java code review and crucial initial access can be established by offensive teams willing to go the extra mile. However, going through that research process for the first time can be intimidating. Acquiring the knowledge necessary for Java offensive code review comes through trial and error, which can delay progress by weeks or months. We’ve recently identified multiple pre-authenticated remote code execution zero days in enterprise Java software. During this presentation, you will learn the effective workflows, strategies, and techniques leveraged for these zero days. You will also hear more about the identified vulnerabilities, the methodology that led to them, and the development process of effective production-ready exploits. We’ll also outline how to avoid common pitfalls when navigating the responsible disclosure process to ensure a successful resolution.