🔓
Exploit Intelligence Centre

Track actively exploited vulnerabilities, emerging threats, and real-world attacker behavior – powered by Rootshell’s Velma platform.

This report is generated using Velma (Vulnerability Enhanced Learning Machine AI) – Rootshell’s exploit intelligence engine.

Velma focuses on one thing: understanding when vulnerabilities actually become a problem.

There’s no shortage of vulnerability data out there, and most of it is driven by static scores. But risk isn’t static. A vulnerability can sit there for months with little real-world relevance, then overnight become critical when exploit code is released or it starts being used in the wild.

Velma tracks that shift.

By analysing exploit availability, attacker activity, and how vulnerabilities are being used in real-world scenarios, Velma highlights what’s genuinely worth paying attention to – not just what’s highly scored, but what’s actually exploitable.

This report provides a current view of the threat landscape, prioritizing vulnerabilities that are actively being weaponised or realistically used in attack paths.

For most organizations, the challenge isn’t a lack of vulnerabilities – it’s knowing which ones actually matter.

Velma Threat Prioritisation Matrix

Continuously updated list of vulnerabilities actively exploited in the wild, helping security teams prioritize what actually matters.

Priority

Threat

CVE

Likelihood

Impact

Exploit Maturity

Velma Risk

1 – CRITICAL

N-able N-central unauthenticated RCE

CVE-2026-86218

Very High

Critical

Possible active exploitation / zero-day

10.0

2 – CRITICAL

Cisco Secure Email Gateway root RCE

CVE-2026-76461

Very High

Critical

Exploitable remotely

9.9

3 – CRITICAL

Cisco FMC authentication bypass to root

CVE-2026-20079

Very High

Critical

Active exploitation

9.9

4 – CRITICAL

SAP Extended Passport remote command execution

CVE-2026-44756

Very High

Critical

Remote / unauthenticated

9.9

5 – CRITICAL

Check Point Quantum Gateway RCE

CVE-2026-85102

Very High

Critical

Remote / unauthenticated

9.8

6 – CRITICAL

ConnectWise ScreenConnect privilege compromise

CVE-2026-84869

High

Critical

Elevated exploitation risk

9.7

7 – CRITICAL

Avada WordPress unauthenticated RCE

CVE-2026-18431

High

Critical

Low-complexity attack path

9.6

8 – CRITICAL

KindaRails2Shell secret disclosure → RCE

CVE-2026-66066

High

Critical

Remote / unauthenticated

9.5

9 – CRITICAL

Langflow arbitrary Python execution

CVE-2026-0768

High

Critical

Remote attack potential

9.5

10 – CRITICAL

Gitea repository-write RCE

CVE-2026-60004

High

Critical

Active exploitation reported

9.4

11 – HIGH

JFrog Artifactory chained admin takeover

CVE-2026-42018 / CVE-2026-42016

High

Critical

Active chained exploitation

9.4

12 – HIGH

WordPress Pods unauthenticated admin takeover

CVE-2026-19598

High

Critical

Remote / unauthenticated

9.3

 

Ready to get started?

1

Discover your needs

Share your security requirements with us, and Rootshell will follow up to ensure we’re the perfect fit for your organization.

2

Dive into a personalized demo

Experience a tailored demonstration of our vulnerability management platform, showcasing how it can enhance your security posture.

3

Seamless onboarding

Start using the Rootshell platform, input previous vulnerability data, and get solutions tailored to your team’s goals, risk appetite, and budget.

Take back control of your cyber
security and see Velma in action!

Yellow square

Take back control of your cyber
security, schedule a demo today!


⚡  GARTNER REPORT


Rootshell recognized in the Gartner® Hype Cycle™ for XaaS, 2026


Explore why security teams are moving from point-in-time testing to continuous, threat-led validation.


Download the Report →