🔓
Exploit Intelligence Centre

Track actively exploited vulnerabilities, emerging threats, and real-world attacker behavior – powered by Rootshell’s Velma platform.

This report is generated using Velma (Vulnerability Enhanced Learning Machine AI) – Rootshell’s exploit intelligence engine.

Velma focuses on one thing: understanding when vulnerabilities actually become a problem.

There’s no shortage of vulnerability data out there, and most of it is driven by static scores. But risk isn’t static. A vulnerability can sit there for months with little real-world relevance, then overnight become critical when exploit code is released or it starts being used in the wild.

Velma tracks that shift.

By analysing exploit availability, attacker activity, and how vulnerabilities are being used in real-world scenarios, Velma highlights what’s genuinely worth paying attention to – not just what’s highly scored, but what’s actually exploitable.

This report provides a current view of the threat landscape, prioritizing vulnerabilities that are actively being weaponised or realistically used in attack paths.

For most organizations, the challenge isn’t a lack of vulnerabilities – it’s knowing which ones actually matter.

Velma Threat Prioritisation Matrix

Continuously updated list of vulnerabilities actively exploited in the wild, helping security teams prioritize what actually matters.

Priority

Threat

CVE

Likelihood

Impact

Exploit Maturity

Velma Risk

Critical

Microsoft Entra ID RCE

CVE-2026-69836

Very High

Critical

Exploited in the Wild

10.0

Critical

SAP Commerce Cloud RCE

CVE-2026-58231

High

Critical

Critical Vulnerability

10.0

Critical

JetBrains TeamCity RCE

CVE-2026-63077

Very High

Critical

Active Exploitation

9.8

Critical

N-able N-central Auth Bypass

CVE-2026-18577

Very High

Critical

Active Exploitation

9.8

Critical

Check Point Admin Auth Bypass

CVE-2026-16232

Very High

Critical

Active Exploitation

9.7

Critical

VMware Authentication Bypass

CVE-2026-59309

High

Critical

Patch Available

9.6

Critical

SharePoint RCE

CVE-2026-50522

High

Critical

High Exploit Potential

9.5

Critical

WordPress SQLi → RCE Chain

CVE-2026-60137 / CVE-2026-63030

High

Critical

Exploit Chain

9.5

Critical

Adobe Commerce / Magento

CVE-2026-71362

Very High

Critical

Reported Exploitation

9.4

High

Windows IKE Remote Code Execution

CVE-2026-33824

High

Critical

Network Exploitable

9.2

High

F5 NGINX Buffer Overflow

CVE-2026-42533

High

Critical

Public PoC

9.1

High

Lazarus Windows Zero-Day

CVE-2026-68820

Very High

High

Active Nation-State Exploitation

9.0

High

Microsoft Defender SYSTEM PrivEsc

CVE-2026-50656

High

High

Public PoC / Patch Bypass

8.8

High

Apple Screen Sharing Auth Bypass

CVE-2026-65400

Medium

High

Network Exploitable

8.4

High

MLflow SSRF

CVE-2026-64849

High

High

Technically Exploitable

8.3

High

Flowise Authenticated RCE

CVE-2026-46442

Medium

Critical

Sandbox Escape / RCE

8.2

High

Windmill Path Traversal

CVE-2026-29059

Very High

High

Active Exploitation

8.2

High

TrueConf Remote Script Execution

CVE-2026-72529

High

High

Network Exploitable

8.0

High

Ray Browser/DNS Rebinding RCE

CVE-2025-62593

Medium

Critical

Exploitable Technique

7.8

Medium

Apache Tomcat Cluster Encryption Bypass

CVE-2026-34486

Medium

High

Patch Available

7.2

Medium

Cisco Static Credentials

CVE-2026-20316*

Medium

Medium

Network Exploitable

6.8

 

Ready to get started?

1

Discover your needs

Share your security requirements with us, and Rootshell will follow up to ensure we’re the perfect fit for your organization.

2

Dive into a personalized demo

Experience a tailored demonstration of our vulnerability management platform, showcasing how it can enhance your security posture.

3

Seamless onboarding

Start using the Rootshell platform, input previous vulnerability data, and get solutions tailored to your team’s goals, risk appetite, and budget.

Take back control of your cyber
security and see Velma in action!

Yellow square

Take back control of your cyber
security, schedule a demo today!