Uploaded May 2026 | Updated September 2026, 6 hours ago
Patrick Garrity (VulnCheck, US), Wade Sparks (VulnCheck, US)
Many high-impact vulnerabilities first emerge through real-world exploitation rather than coordinated disclosure, leaving defenders without reliable identifiers at the moment risk is greatest. In 2025, the VulnCheck research team launched a project to identify vulnerabilities that are actively exploited or likely to be exploited but lack CVE identifiers. This talk presents the methodology and lessons learned from correlating exploitation evidence, public exploit code, security advisories, in-house detection capabilities, and third-party intelligence sources such as ShadowServer. We walk through our end-to-end workflow for auditing sources, mapping findings to existing CVEs, and navigating the CVE assignment or coordination process when gaps are identified. Attendees will gain insight into blind spots in current vulnerability tracking, how exploitation often precedes formal disclosure, and practical steps for surfacing and tracking the vulnerabilities that matter most to defenders.
---
Patrick Garrity is a security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors.
Wade Sparks is a senior vulnerability analyst at VulnCheck, where he manages coordinated vulnerability disclosure (CVD) operations and contributes to VulnCheck’s role as a CVE Numbering Authority (CNA). He is passionate about ensuring vulnerabilities are accurately identified and disclosed with clear remediation guidance in a timely, coordinated manner.
Patrick Garrity (VulnCheck, US), Wade Sparks (VulnCheck, US)
Many high-impact vulnerabilities first emerge through real-world exploitation rather than coordinated disclosure, leaving defenders without reliable identifiers at the moment risk is greatest. In 2025, the VulnCheck research team launched a project to identify vulnerabilities that are actively exploited or likely to be exploited but lack CVE identifiers. This talk presents the methodology and lessons learned from correlating exploitation evidence, public exploit code, security advisories, in-house detection capabilities, and third-party intelligence sources such as ShadowServer. We walk through our end-to-end workflow for auditing sources, mapping findings to existing CVEs, and navigating the CVE assignment or coordination process when gaps are identified. Attendees will gain insight into blind spots in current vulnerability tracking, how exploitation often precedes formal disclosure, and practical steps for surfacing and tracking the vulnerabilities that matter most to defenders.
---
Patrick Garrity is a security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors.
Wade Sparks is a senior vulnerability analyst at VulnCheck, where he manages coordinated vulnerability disclosure (CVD) operations and contributes to VulnCheck’s role as a CVE Numbering Authority (CNA). He is passionate about ensuring vulnerabilities are accurately identified and disclosed with clear remediation guidance in a timely, coordinated manner.










