Junglewise

Monthly report

Most vulnerable technologies in March 2026

Final report, published . It does not change.

In March 2026, Junglewise Threat Intelligence recorded 1,652 new vulnerabilities: 147 critical, 442 high and 25 exploited in the wild. The most vulnerable technology was Openclaw, with 302 vulnerabilities (5 critical), followed by Linux Kernel (117) and Apple macOS (30).

New vulnerabilities
1,652
Critical
147
Exploited in the wild
25
Technologies affected
1,075

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Openclaw
Openclaw
30251909.9
2Linux Kernel
Linux
11744009.8
3Apple macOS
Apple
3051339.8
4Mozilla Thunderbird
Mozilla
211011010
5Mozilla Firefox
Mozilla
201010010
6Mozilla Firefox ESR
Mozilla
19910010
7Apple Multiple Products
Apple
55059.8
8Apple iPadOS
Apple
164148.8
9Apple watchOS
Apple
104048.8
10Microsoft Windows
Microsoft
1721509.8
11Apple tvOS
Apple
83038.8
12Google Android
Google
113719.8
13Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
Siemens
2401107.8
14Apple visionOS
Apple
132027.8
15Langflow
Langflow
83519.9
16Mozilla Thunderbird-Esr
Mozilla
853010
17Cisco Secure Firewall Management Center
Cisco
521210
18Google Chrome
Google
32128.8
19Cisco Secure Firewall Management Center (FMC)
Cisco
320210
20Cisco Security Cloud Control
Cisco
220210
21Lantronix EDS5008
Lantronix
52319.8
22Lantronix Eds5008 Firmware
Lantronix
52319.8
23Lantronix EDS5016
Lantronix
52319.8
24Lantronix Eds5016 Firmware
Lantronix
52319.8
25Lantronix EDS5032
Lantronix
52319.8

Most affected vendors

  1. 1.Openclaw302 vulnerabilities, 5 critical, 0 exploited
  2. 2.Npm185 vulnerabilities, 7 critical, 0 exploited
  3. 3.Red Hat84 vulnerabilities, 9 critical, 0 exploited
  4. 4.Linux117 vulnerabilities, 4 critical, 0 exploited
  5. 5.Apple34 vulnerabilities, 8 critical, 6 exploited
  6. 6.Microsoft31 vulnerabilities, 4 critical, 2 exploited
  7. 7.Cisco48 vulnerabilities, 3 critical, 3 exploited
  8. 8.Mozilla21 vulnerabilities, 10 critical, 0 exploited
  9. 9.Pip36 vulnerabilities, 2 critical, 0 exploited
  10. 10.Adobe44 vulnerabilities, 0 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/monthly/2026-03.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in March 2026", https://junglewise.ai/threats/monthly/2026-03, 26 September 2026.