🔓
Exploit Intelligence Centre
Track actively exploited vulnerabilities, emerging threats, and real-world attacker behavior – powered by Rootshell’s Velma platform.
This report is generated using Velma (Vulnerability Enhanced Learning Machine AI) – Rootshell’s exploit intelligence engine.
Velma focuses on one thing: understanding when vulnerabilities actually become a problem.
There’s no shortage of vulnerability data out there, and most of it is driven by static scores. But risk isn’t static. A vulnerability can sit there for months with little real-world relevance, then overnight become critical when exploit code is released or it starts being used in the wild.
Velma tracks that shift.
By analysing exploit availability, attacker activity, and how vulnerabilities are being used in real-world scenarios, Velma highlights what’s genuinely worth paying attention to – not just what’s highly scored, but what’s actually exploitable.
This report provides a current view of the threat landscape, prioritizing vulnerabilities that are actively being weaponised or realistically used in attack paths.
For most organizations, the challenge isn’t a lack of vulnerabilities – it’s knowing which ones actually matter.
Velma Threat Prioritisation Matrix
Continuously updated list of vulnerabilities actively exploited in the wild, helping security teams prioritize what actually matters.
Priority | Threat | CVE | Likelihood | Impact | Exploit Maturity | Velma Risk Score |
1 | Ubiquiti UniFi OS Active Exploitation Cluster | CVE-2026-34908 / 34909 / 34910 | Very High | Very High | High | 10.0 (Critical) |
2 | Adobe ColdFusion Unauthenticated RCE Cluster | CVE-2026-48276 / 48277 / 48281 / 48282 / 48283 / 48316 | Very High | Very High | High | 10.0 (Critical) |
3 | SonicWall SMA Zero-Day Exploitation | CVE-2026-15409 / 15410 | Very High | Very High | High | 9.9 (Critical) |
4 | SharePoint Remote Privilege Escalation | CVE-2026-56164 | Very High | Very High | High | 9.9 (Critical) |
5 | Progress Kemp LoadMaster Command Injection | CVE-2026-8037 | Very High | Very High | High | 9.8 (Critical) |
6 | SimpleHelp OIDC Authentication Bypass | CVE-2026-48558 | Very High | Very High | High | 9.8 (Critical) |
7 | Oracle Payments Instance Takeover | CVE-2026-46817 | Very High | Very High | High | 9.7 (Critical) |
8 | Tenda Administrative Backdoor | CVE-2026-11405 | Very High | Very High | High | 9.7 (Critical) |
9 | PTC Windchill Remote Code Execution | CVE-2026-12569 | Very High | Very High | High | 9.6 (Critical) |
10 | Microsoft AD FS Privilege Escalation | CVE-2026-56155 | High | Very High | High | 9.5 (Critical) |
11 | BeyondTrust Authentication Vulnerability Cluster | CVE-2026-40138 / 40139 | High | Very High | High | 9.5 (Critical) |
12 | SAP Kernel Memory Corruption | CVE-2026-44747 | High | Very High | Medium | 9.4 (Critical) |
13 | Lantronix EDS5000 Root Command Injection | CVE-2025-67038 | High | Very High | High | 9.4 (Critical) |
14 | Zoom Workplace Account Takeover | CVE-2026-53412 | High | Very High | Medium | 9.3 (Critical) |
15 | libssh2 Remote Code Execution | CVE-2026-55200 | High | Very High | Medium | 9.2 (Critical) |
16 | F5 NGINX HTTP/3 and HTTP/2 RCE Cluster | CVE-2026-42530 / 42055 | High | Very High | Medium | 9.1 (Critical) |
17 | Cisco SSRF and Root Escalation Path | CVE-2026-20230 | High | High | Medium | 8.9 (High) |
18 | FFmpeg Crafted Media RCE | CVE-2026-8461 | High | High | Medium | 8.8 (High) |
19 | Palo Alto PAN-OS Memory Corruption | CVE-2026-0288 | Medium | Very High | Medium | 8.5 (High) |
20 | SAP Approuter Request Smuggling | CVE-2026-27690 | Medium | High | Medium | 8.4 (High) |
21 | SAP Commerce Cloud Default Credentials | CVE-2026-44761 | Medium | High | Medium | 8.3 (High) |
22 | Adobe ColdFusion File Read / Privilege Escalation | CVE-2026-48313 / 48315 | Medium | High | Medium | 8.2 (High) |
23 | BeyondTrust DoS and Data Query Injection | CVE-2026-40140 / 40141 | Medium | High | Medium | 8.0 (High) |
24 | Ubiquiti Additional UniFi OS Vulnerabilities | CVE-2026-33000 / 34911 | Medium | High | Medium | 7.9 (Medium) |
Latest Velma KEV Reports
Velma’s KEV Report – July 2026
Velma’s KEV Report – June 2026
Velma’s KEV Report – May 2026
Velma’s KEV Report – April 2026
Velma’s KEV Report – March 2026
Velma’s KEV Report – February 2026
Velma’s KEV Report – January 2026
Velma’s KEV Report – December 2025
Velma’s KEV Report – Oct & November 2025
Ready to get started?
1
Discover your needs
2
Dive into a personalized demo
3
