CALL FOR PAPERS

16th & 17th of October 2026 | Palais Brongniart, 16 Place de la Bourse, 75002 Paris

Have some cool research you want to showcase to the Offensive Security community?

Take a moment to read what Hexacon expects from a talk application, or jump right out to our CFP platform! Alternatively you can take a look at last year’s schedule to see what talks were accepted.

Important dates

  • CFP closes on the 1st of August 2026 at 23:59
  • Talks selection in August
  • Hexacon 2026: 16th & 17th of October 2026

Would you like to share your novel / interesting research work in any of these topics?

Vulnerability Research

Exploitation Techniques

Cryptography Attacks

Hardware Hacking

Application Security

OS, virtualization and low-level Security

Short Distance Attacks

Post-exploitation Techniques

Benefits for speakers

Present your research to the world

Speak in front of an expert crowd. Your talk will also be recorded (if you agree), archived publicly and can be used later on as a reference in bibliographies

Last year's edition videos can be found here

Speaker Dinner

Spend an evening with other speakers, trainers and program committee members

Travel expenses covered

Speakers are what makes the conference truly unique, that’s why it’s only fair to help you come to Paris, logistically and financially

Thus we will provide a free hotel room for the duration of the event and travel costs are reimbursed up to 2000€, limited to two speakers

About your potential application

Submitters are expected to provide some information about the talk they want to present in order for the committee to fairly grade them against other applications.

Each application can list up to 3 speakers, and must respect either the 30 or 45 minutes format.

What you should include

Your name or pseudonym, and contact information

Presentation title and duration (30 or 45 minutes)

A detailed abstract: the more context and technical depth you provide, the better the committee can assess your submission. Vague abstracts are likely to be ranked lower regardless of the quality of the underlying research

Overall outline of the talk

Past speaking experience if you have some, especially if those are in English

Additional recommendations

Ensure the content of your talk has real-world relevance and provides inspiration for further work for the listener

The subject does not have to be truly novel or original, but in that case it must aim for state of the art knowledge

Express clearly why people would want to attend your talk and what their takeaways will be

Give your proposal a title that entices people to know more about it

All speakers must be added before the CFP closes

About the conference

Hexacon is a single-track security conference focused on technical offensive security talks

The conference will take place from the 16th of October 2026 to the 17th, in the heart of Paris

Every talk will be in English, without translations or subtitles

Two social events will be organized on the evenings of October 16th and 17th

Trainings will take place during the 4 days preceding the conference

How to submit your application

1

Follow the link below to go to the CFP platform and fill the form for your application. CFP is open until the 1st of August 2026 at 23:59

2

The review committee will examine your application and accept it or not. Expect an answer (positive or not) by the end of August 2026.

3

Upon acceptance of your application, you will be contacted to smooth out logistical details regarding your coming, and you will be asked additional info such as a biography, photo, etc.

4

In the unfortunate event that you can’t physically come to Hexacon to deliver your talk, your slot will be reallocated to someone who can.

5

Enjoy Hexacon and Paris in the fall!

Who will judge your submission?

11 professionals | 8 nationalities | 65535 vulnerabilities found

The review committee was created by gathering many experts of the community that best represent the variety and diversity of technical knowledge and viewpoints, in order to make Hexacon a truly global conference.

Jean-Baptiste
BEDRUNE


@33c0

Amat
CAMA


@amatcama

Jiska
Classen

Hasso Plattner Institute
@naehrdine

Marco
GRASSI


@marcograss

Ophir
HARPAZ

Akamai
@OphirHarpaz

Bruno
KEITH

Dataflow Security
@bkth_

Valentina
PALMIOTTI

IBM X-Force
@chompie1337

Fabien
PERIGAUD

Synacktiv
@0xF4b

Perri
Adams


@perribus

Axel
SOUCHET


@0vercl0k

Gabrielle
VIALA


@pwissenlit