Monthly report
Most vulnerable technologies in March 2026
Final report, published . It does not change.
In March 2026, Junglewise Threat Intelligence recorded 1,652 new vulnerabilities: 147 critical, 442 high and 25 exploited in the wild. The most vulnerable technology was Openclaw, with 302 vulnerabilities (5 critical), followed by Linux Kernel (117) and Apple macOS (30).
- New vulnerabilities
- 1,652
- Critical
- 147
- Exploited in the wild
- 25
- Technologies affected
- 1,075
Ranking
Most affected vendors
- 1.Openclaw302 vulnerabilities, 5 critical, 0 exploited
- 2.Npm185 vulnerabilities, 7 critical, 0 exploited
- 3.Red Hat84 vulnerabilities, 9 critical, 0 exploited
- 4.Linux117 vulnerabilities, 4 critical, 0 exploited
- 5.Apple34 vulnerabilities, 8 critical, 6 exploited
- 6.Microsoft31 vulnerabilities, 4 critical, 2 exploited
- 7.Cisco48 vulnerabilities, 3 critical, 3 exploited
- 8.Mozilla21 vulnerabilities, 10 critical, 0 exploited
- 9.Pip36 vulnerabilities, 2 critical, 0 exploited
- 10.Adobe44 vulnerabilities, 0 critical, 0 exploited
Most severe vulnerabilities
- CVE-2025-32432: Craft CMS remote code execution via code injectioncriticalexploited in the wildCVSS 10EPSS 92.7%
- CVE-2026-20079: Cisco Secure Firewall Management Center auth bypass in web interfacecriticalexploited in the wildCVSS 10EPSS 88.2%
- CVE-2026-20131: Cisco Secure Firewall Management Center deserialization RCEcriticalexploited in the wildCVSS 10EPSS 1.7%
- CVE-2017-7921: Hikvision IP Cameras improper authenticationcriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2026-3055: Citrix NetScaler out-of-bounds read in SAML IdPcriticalexploited in the wildCVSS 9.8EPSS 74.1%
- CVE-2025-54068: Laravel Livewire code injection in component hydrationcriticalexploited in the wildCVSS 9.8EPSS 64.1%
- CVE-2025-26399: SolarWinds Web Help Desk deserialization RCE in AjaxProxycriticalexploited in the wildCVSS 9.8EPSS 27.8%
- CVE-2026-33017: Langflow unauthenticated remote code execution in build_public_tmp endpointcriticalexploited in the wildCVSS 9.8EPSS 24.6%
- CVE-2021-22681: Rockwell Automation Logix Designer authentication bypass in Logix Controllerscriticalexploited in the wildCVSS 9.8EPSS 18.2%
- CVE-2025-53521: F5 BIG-IP stack-based buffer overflow in APMcriticalexploited in the wildCVSS 9.8EPSS 7.4%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/monthly/2026-03.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in March 2026", https://junglewise.ai/threats/monthly/2026-03, 26 September 2026.