Vulnerability Intelligence

The public CVE record plus KELA's underground intelligence equals the real severity: patch now – KELA

The formal vulnerability stack is correct, and incomplete

Where the gap opens

Where the gap opens – KELA Vulnerability Intelligence

CVE-2026-27825: from patch to criminal exploit

  • 24 February 2026. Version 0.17.0 ships the fix. CVE-2026-27825 (CVSS 9.1) and CVE-2026-27826 (CVSS 8.2) are issued.
  • 26 February 2026. Pluto Security publishes the MCPwnfluence analysis. No active exploitation observed.
  • 10 March 2026. Both CVEs are published on the NVD. The vulnerabilities are now public knowledge.
  • 16 March 2026. KELA analysts identify a full exploitation writeup with a working proof of concept on XSS.PRO, a long-running Russian-language criminal forum, distributed through its .onion address.
  • 9 September 2026. CVE-2026-27825 is still not in CISA’s KEV catalog. EPSS rates it 2.3%, Low.
CVE-2026-27825 means we need to talk about KEV, CVE and CVSS: the KELA blog post

How KELA closes the gap

Collection where exploits are built

Mapped to the CVE IDs you already track

Evidence that changes the patch order

Internet-facing assets mapped to the CVEs criminals target – KELA

Your infrastructure, seen the way attackers see it

One place for every CVE

Search by CVE or product – KELA

Search by CVE or product

Scores side by side – KELA

Scores side by side

Mitigation steps – KELA

Mitigation steps

Affected products – KELA

Affected products

CWE to MITRE ATT&CK – KELA

CWE to MITRE ATT&CK

The underground record – KELA

The underground record

Book a Demo

FAQ

What is vulnerability intelligence?
How is it different from CVSS, EPSS and KEV?
Does this replace my vulnerability scanner or EPSS?
Does KELA show which of my assets are affected?
How does the intelligence reach my team?