{"schema_version":1,"title":"Most vulnerable technologies in March 2026","summary":"In March 2026, Junglewise Threat Intelligence recorded 1,652 new vulnerabilities: 147 critical, 442 high and 25 exploited in the wild. The most vulnerable technology was Openclaw, with 302 vulnerabilities (5 critical), followed by Linux Kernel (117) and Apple macOS (30).","url":"https://junglewise.ai/threats/monthly/2026-03","json_url":"https://junglewise.ai/threats/monthly/2026-03.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/monthly/2026-03","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"month","period":{"end":"2026-03-31","start":"2026-03-01"},"totals":{"high":442,"critical":147,"exploited":25,"technologies":1075,"vulnerabilities":1652},"notable":[{"cve":"CVE-2025-32432","cvss":10,"epss":0.9265,"slug":"cve-2025-32432-craft-cms-remote-code-execution-via-code-injection","title":"Craft CMS remote code execution via code injection","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-32432-craft-cms-remote-code-execution-via-code-injection"},{"cve":"CVE-2026-20079","cvss":10,"epss":0.8818,"slug":"cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web","title":"Cisco Secure Firewall Management Center auth bypass in web interface","severity":"critical","exploited":true,"published_at":"2026-03-04T18:16:24.23+00:00","url":"https://junglewise.ai/threats/cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web"},{"cve":"CVE-2026-20131","cvss":10,"epss":0.0172,"slug":"cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce","title":"Cisco Secure Firewall Management Center deserialization RCE","severity":"critical","exploited":true,"published_at":"2026-03-19T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce"},{"cve":"CVE-2017-7921","cvss":9.8,"epss":0.9423,"slug":"cve-2017-7921-hikvision-ip-cameras-improper-authentication","title":"Hikvision IP Cameras improper authentication","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-7921-hikvision-ip-cameras-improper-authentication"},{"cve":"CVE-2026-3055","cvss":9.8,"epss":0.7409,"slug":"cve-2026-3055-citrix-netscaler-out-of-bounds-read-in-saml-idp","title":"Citrix NetScaler out-of-bounds read in SAML IdP","severity":"critical","exploited":true,"published_at":"2026-03-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-3055-citrix-netscaler-out-of-bounds-read-in-saml-idp"},{"cve":"CVE-2025-54068","cvss":9.8,"epss":0.6406,"slug":"cve-2025-54068-laravel-livewire-code-injection-in-component-hydration","title":"Laravel Livewire code injection in component hydration","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-54068-laravel-livewire-code-injection-in-component-hydration"},{"cve":"CVE-2025-26399","cvss":9.8,"epss":0.2776,"slug":"cve-2025-26399-solarwinds-web-help-desk-deserialization-rce-in-ajaxproxy","title":"SolarWinds Web Help Desk deserialization RCE in AjaxProxy","severity":"critical","exploited":true,"published_at":"2026-03-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-26399-solarwinds-web-help-desk-deserialization-rce-in-ajaxproxy"},{"cve":"CVE-2026-33017","cvss":9.8,"epss":0.2465,"slug":"cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public","title":"Langflow unauthenticated remote code execution in build_public_tmp endpoint","severity":"critical","exploited":true,"published_at":"2026-03-20T05:16:15.55+00:00","url":"https://junglewise.ai/threats/cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public"},{"cve":"CVE-2021-22681","cvss":9.8,"epss":0.1816,"slug":"cve-2021-22681-rockwell-automation-logix-designer-authentication-bypass-in-logix","title":"Rockwell Automation Logix Designer authentication bypass in Logix Controllers","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-22681-rockwell-automation-logix-designer-authentication-bypass-in-logix"},{"cve":"CVE-2025-53521","cvss":9.8,"epss":0.0745,"slug":"cve-2025-53521-f5-big-ip-stack-based-buffer-overflow-in-apm","title":"F5 BIG-IP stack-based buffer overflow in APM","severity":"critical","exploited":true,"published_at":"2026-03-27T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-53521-f5-big-ip-stack-based-buffer-overflow-in-apm"}],"vendors":[{"hub":true,"high":19,"name":"Openclaw","rank":1,"slug":"openclaw","critical":5,"exploited":0,"vulnerabilities":302,"url":"https://junglewise.ai/threats/vendors/openclaw"},{"hub":true,"high":22,"name":"Npm","rank":2,"slug":"npm","critical":7,"exploited":0,"vulnerabilities":185,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":56,"name":"Red Hat","rank":3,"slug":"red-hat","critical":9,"exploited":0,"vulnerabilities":84,"url":"https://junglewise.ai/threats/vendors/red-hat"},{"hub":true,"high":40,"name":"Linux","rank":4,"slug":"linux","critical":4,"exploited":0,"vulnerabilities":117,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":13,"name":"Apple","rank":5,"slug":"apple","critical":8,"exploited":6,"vulnerabilities":34,"url":"https://junglewise.ai/threats/vendors/apple"},{"hub":true,"high":25,"name":"Microsoft","rank":6,"slug":"microsoft","critical":4,"exploited":2,"vulnerabilities":31,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":11,"name":"Cisco","rank":7,"slug":"cisco","critical":3,"exploited":3,"vulnerabilities":48,"url":"https://junglewise.ai/threats/vendors/cisco"},{"hub":true,"high":11,"name":"Mozilla","rank":8,"slug":"mozilla","critical":10,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/vendors/mozilla"},{"hub":true,"high":22,"name":"Pip","rank":9,"slug":"pip","critical":2,"exploited":0,"vulnerabilities":36,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":20,"name":"Adobe","rank":10,"slug":"adobe","critical":0,"exploited":0,"vulnerabilities":44,"url":"https://junglewise.ai/threats/vendors/adobe"}],"generated_at":"2026-09-26T10:07:00.179841+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-33579","cvss":9.9,"epss":0.0051,"slug":"cve-2026-33579-openclaw-privilege-escalation-in-device-pairing-approval","title":"OpenClaw privilege escalation in device pairing approval","severity":"critical","exploited":false,"published_at":"2026-03-31T15:16:14.96+00:00","url":"https://junglewise.ai/threats/cve-2026-33579-openclaw-privilege-escalation-in-device-pairing-approval"},{"cve":"CVE-2026-32917","cvss":9.8,"epss":0.032,"slug":"cve-2026-32917-openclaw-remote-command-injection-in-imessage-attachment-staging","title":"OpenClaw remote command injection in iMessage attachment staging","severity":"critical","exploited":false,"published_at":"2026-03-31T12:16:28.487+00:00","url":"https://junglewise.ai/threats/cve-2026-32917-openclaw-remote-command-injection-in-imessage-attachment-staging"},{"cve":"CVE-2026-28474","cvss":9.8,"epss":0.0085,"slug":"cve-2026-28474-openclaw-nextcloud-talk-allowlist-bypass-via-display-name","title":"OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowl","severity":"critical","exploited":false,"published_at":"2026-03-05T22:16:21.423+00:00","url":"https://junglewise.ai/threats/cve-2026-28474-openclaw-nextcloud-talk-allowlist-bypass-via-display-name"}],"high":19,"name":"Openclaw","rank":1,"slug":"openclaw","score":365,"vendor":{"name":"Openclaw","slug":"openclaw"},"critical":5,"max_cvss":9.9,"max_epss":0.032,"exploited":0,"vulnerabilities":302,"url":"https://junglewise.ai/threats/technologies/openclaw"},{"hub":true,"top":[{"cve":"CVE-2026-3843","cvss":9.8,"epss":0.0094,"slug":"cve-2026-3843-nefteprodukttekhnika-buk-ts-g-sql-injection-in-configuration","title":"Nefteprodukttekhnika BUK TS-G SQL injection in configuration module","severity":"critical","exploited":false,"published_at":"2026-03-10T18:19:05.287+00:00","url":"https://junglewise.ai/threats/cve-2026-3843-nefteprodukttekhnika-buk-ts-g-sql-injection-in-configuration"},{"cve":"CVE-2026-23240","cvss":9.8,"epss":0.0007,"slug":"cve-2026-23240-linux-kernel-race-condition-in-tls-sw-cancel-work-tx","title":"Linux Kernel race condition in tls_sw_cancel_work_tx","severity":"critical","exploited":false,"published_at":"2026-03-10T18:18:13.533+00:00","url":"https://junglewise.ai/threats/cve-2026-23240-linux-kernel-race-condition-in-tls-sw-cancel-work-tx"},{"cve":"CVE-2026-30789","cvss":9.8,"epss":0.0042,"slug":"cve-2026-30789-rustdesk-client-authentication-bypass-via-session-replay-and-weak","title":"RustDesk Client authentication bypass via session replay and weak hashing","severity":"critical","exploited":false,"published_at":"2026-03-05T16:16:19.56+00:00","url":"https://junglewise.ai/threats/cve-2026-30789-rustdesk-client-authentication-bypass-via-session-replay-and-weak"}],"high":40,"name":"Linux Kernel","rank":2,"slug":"kernel","score":217,"vendor":{"name":"Linux","slug":"linux"},"critical":4,"max_cvss":9.8,"max_epss":0.0094,"exploited":0,"vulnerabilities":117,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2025-43510","cvss":7.8,"epss":0.003,"slug":"cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory","title":"Apple Multiple Products improper locking in shared memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory"},{"cve":"CVE-2023-41974","cvss":7.8,"epss":0.0022,"slug":"cve-2023-41974-apple-ios-and-ipados-use-after-free-in-kernel","title":"Apple iOS and iPadOS use-after-free in kernel","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-41974-apple-ios-and-ipados-use-after-free-in-kernel"},{"cve":"CVE-2025-43520","cvss":5.5,"epss":0.0027,"slug":"cve-2025-43520-apple-multiple-products-classic-buffer-overflow-in-kernel-memory","title":"Apple Multiple Products classic buffer overflow in kernel memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43520-apple-multiple-products-classic-buffer-overflow-in-kernel-memory"}],"high":13,"name":"Apple macOS","rank":3,"slug":"macos-tahoe","score":111,"vendor":{"name":"Apple","slug":"apple"},"critical":5,"max_cvss":9.8,"max_epss":0.0072,"exploited":3,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-4692","cvss":10,"epss":0.0039,"slug":"cve-2026-4692-mozilla-firefox-and-thunderbird-sandbox-escape-in-responsive","title":"Mozilla Firefox and Thunderbird sandbox escape in Responsive Design Mode","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:05.04+00:00","url":"https://junglewise.ai/threats/cve-2026-4692-mozilla-firefox-and-thunderbird-sandbox-escape-in-responsive"},{"cve":"CVE-2026-4689","cvss":10,"epss":0.0068,"slug":"cve-2026-4689-mozilla-firefox-and-thunderbird-sandbox-escape-in-xpcom","title":"Mozilla Firefox and Thunderbird sandbox escape in XPCOM","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:04.737+00:00","url":"https://junglewise.ai/threats/cve-2026-4689-mozilla-firefox-and-thunderbird-sandbox-escape-in-xpcom"},{"cve":"CVE-2026-4688","cvss":10,"epss":0.0041,"slug":"cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability","title":"Mozilla Firefox and Thunderbird sandbox escape in Disability Access APIs","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:04.64+00:00","url":"https://junglewise.ai/threats/cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability"}],"high":11,"name":"Mozilla Thunderbird","rank":4,"slug":"thunderbird","score":93,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":10,"max_cvss":10,"max_epss":0.0068,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/thunderbird"},{"hub":true,"top":[{"cve":"CVE-2026-4692","cvss":10,"epss":0.0039,"slug":"cve-2026-4692-mozilla-firefox-and-thunderbird-sandbox-escape-in-responsive","title":"Mozilla Firefox and Thunderbird sandbox escape in Responsive Design Mode","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:05.04+00:00","url":"https://junglewise.ai/threats/cve-2026-4692-mozilla-firefox-and-thunderbird-sandbox-escape-in-responsive"},{"cve":"CVE-2026-4689","cvss":10,"epss":0.0068,"slug":"cve-2026-4689-mozilla-firefox-and-thunderbird-sandbox-escape-in-xpcom","title":"Mozilla Firefox and Thunderbird sandbox escape in XPCOM","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:04.737+00:00","url":"https://junglewise.ai/threats/cve-2026-4689-mozilla-firefox-and-thunderbird-sandbox-escape-in-xpcom"},{"cve":"CVE-2026-4688","cvss":10,"epss":0.0041,"slug":"cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability","title":"Mozilla Firefox and Thunderbird sandbox escape in Disability Access APIs","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:04.64+00:00","url":"https://junglewise.ai/threats/cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability"}],"high":10,"name":"Mozilla Firefox","rank":5,"slug":"firefox","score":90,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":10,"max_cvss":10,"max_epss":0.0068,"exploited":0,"vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/firefox"},{"hub":true,"top":[{"cve":"CVE-2026-4692","cvss":10,"epss":0.0039,"slug":"cve-2026-4692-mozilla-firefox-and-thunderbird-sandbox-escape-in-responsive","title":"Mozilla Firefox and Thunderbird sandbox escape in Responsive Design Mode","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:05.04+00:00","url":"https://junglewise.ai/threats/cve-2026-4692-mozilla-firefox-and-thunderbird-sandbox-escape-in-responsive"},{"cve":"CVE-2026-4689","cvss":10,"epss":0.0068,"slug":"cve-2026-4689-mozilla-firefox-and-thunderbird-sandbox-escape-in-xpcom","title":"Mozilla Firefox and Thunderbird sandbox escape in XPCOM","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:04.737+00:00","url":"https://junglewise.ai/threats/cve-2026-4689-mozilla-firefox-and-thunderbird-sandbox-escape-in-xpcom"},{"cve":"CVE-2026-4688","cvss":10,"epss":0.0041,"slug":"cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability","title":"Mozilla Firefox and Thunderbird sandbox escape in Disability Access APIs","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:04.64+00:00","url":"https://junglewise.ai/threats/cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability"}],"high":10,"name":"Mozilla Firefox ESR","rank":6,"slug":"firefox-esr","score":84,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":9,"max_cvss":10,"max_epss":0.0068,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/firefox-esr"},{"hub":true,"top":[{"cve":"CVE-2017-7921","cvss":9.8,"epss":0.9423,"slug":"cve-2017-7921-hikvision-ip-cameras-improper-authentication","title":"Hikvision IP Cameras improper authentication","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-7921-hikvision-ip-cameras-improper-authentication"},{"cve":"CVE-2021-22681","cvss":9.8,"epss":0.1816,"slug":"cve-2021-22681-rockwell-automation-logix-designer-authentication-bypass-in-logix","title":"Rockwell Automation Logix Designer authentication bypass in Logix Controllers","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-22681-rockwell-automation-logix-designer-authentication-bypass-in-logix"},{"cve":"CVE-2021-30952","cvss":8.8,"epss":0.0089,"slug":"cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content","title":"Apple Multiple Products integer overflow in WebKit content processing","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content"}],"high":0,"name":"Apple Multiple Products","rank":7,"slug":"multiple-products","score":80,"vendor":{"name":"Apple","slug":"apple"},"critical":5,"max_cvss":9.8,"max_epss":0.9423,"exploited":5,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/multiple-products"},{"hub":true,"top":[{"cve":"CVE-2021-30952","cvss":8.8,"epss":0.0089,"slug":"cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content","title":"Apple Multiple Products integer overflow in WebKit content processing","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content"},{"cve":"CVE-2025-43510","cvss":7.8,"epss":0.003,"slug":"cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory","title":"Apple Multiple Products improper locking in shared memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory"},{"cve":"CVE-2023-41974","cvss":7.8,"epss":0.0022,"slug":"cve-2023-41974-apple-ios-and-ipados-use-after-free-in-kernel","title":"Apple iOS and iPadOS use-after-free in kernel","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-41974-apple-ios-and-ipados-use-after-free-in-kernel"}],"high":1,"name":"Apple iPadOS","rank":8,"slug":"ipados","score":78,"vendor":{"name":"Apple","slug":"apple"},"critical":4,"max_cvss":8.8,"max_epss":0.0089,"exploited":4,"vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ipados"},{"hub":true,"top":[{"cve":"CVE-2021-30952","cvss":8.8,"epss":0.0089,"slug":"cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content","title":"Apple Multiple Products integer overflow in WebKit content processing","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content"},{"cve":"CVE-2025-43510","cvss":7.8,"epss":0.003,"slug":"cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory","title":"Apple Multiple Products improper locking in shared memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory"},{"cve":"CVE-2023-41974","cvss":7.8,"epss":0.0022,"slug":"cve-2023-41974-apple-ios-and-ipados-use-after-free-in-kernel","title":"Apple iOS and iPadOS use-after-free in kernel","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-41974-apple-ios-and-ipados-use-after-free-in-kernel"}],"high":0,"name":"Apple watchOS","rank":9,"slug":"watchos","score":70,"vendor":{"name":"Apple","slug":"apple"},"critical":4,"max_cvss":8.8,"max_epss":0.0089,"exploited":4,"vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/watchos"},{"hub":true,"top":[{"cve":"CVE-2026-30789","cvss":9.8,"epss":0.0042,"slug":"cve-2026-30789-rustdesk-client-authentication-bypass-via-session-replay-and-weak","title":"RustDesk Client authentication bypass via session replay and weak hashing","severity":"critical","exploited":false,"published_at":"2026-03-05T16:16:19.56+00:00","url":"https://junglewise.ai/threats/cve-2026-30789-rustdesk-client-authentication-bypass-via-session-replay-and-weak"},{"cve":"CVE-2026-30783","cvss":9.8,"epss":0.0059,"slug":"cve-2026-30783-rustdesk-client-privilege-abuse-via-unauthenticated-strategy","title":"RustDesk Client privilege abuse via unauthenticated strategy injection","severity":"critical","exploited":false,"published_at":"2026-03-05T16:16:18.91+00:00","url":"https://junglewise.ai/threats/cve-2026-30783-rustdesk-client-privilege-abuse-via-unauthenticated-strategy"},{"cve":"CVE-2026-30794","cvss":8.1,"epss":0.0031,"slug":"cve-2026-30794-rustdesk-client-improper-certificate-validation-in-tls-transport","title":"RustDesk Client improper certificate validation in TLS transport modules","severity":"high","exploited":false,"published_at":"2026-03-05T16:16:20.177+00:00","url":"https://junglewise.ai/threats/cve-2026-30794-rustdesk-client-improper-certificate-validation-in-tls-transport"}],"high":15,"name":"Microsoft Windows","rank":10,"slug":"windows-","score":57,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":2,"max_cvss":9.8,"max_epss":0.0059,"exploited":0,"vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2021-30952","cvss":8.8,"epss":0.0089,"slug":"cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content","title":"Apple Multiple Products integer overflow in WebKit content processing","severity":"critical","exploited":true,"published_at":"2026-03-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-30952-apple-multiple-products-integer-overflow-in-webkit-content"},{"cve":"CVE-2025-43510","cvss":7.8,"epss":0.003,"slug":"cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory","title":"Apple Multiple Products improper locking in shared memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory"},{"cve":"CVE-2025-43520","cvss":5.5,"epss":0.0027,"slug":"cve-2025-43520-apple-multiple-products-classic-buffer-overflow-in-kernel-memory","title":"Apple Multiple Products classic buffer overflow in kernel memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43520-apple-multiple-products-classic-buffer-overflow-in-kernel-memory"}],"high":0,"name":"Apple tvOS","rank":11,"slug":"tvos","score":53,"vendor":{"name":"Apple","slug":"apple"},"critical":3,"max_cvss":8.8,"max_epss":0.0089,"exploited":3,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/tvos"},{"hub":true,"top":[{"cve":"CVE-2026-3909","cvss":8.8,"epss":0.0039,"slug":"cve-2026-3909-google-skia-out-of-bounds-write-in-google-chrome","title":"Google Skia out-of-bounds write in Google Chrome","severity":"critical","exploited":true,"published_at":"2026-03-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-3909-google-skia-out-of-bounds-write-in-google-chrome"},{"cve":"CVE-2026-30789","cvss":9.8,"epss":0.0042,"slug":"cve-2026-30789-rustdesk-client-authentication-bypass-via-session-replay-and-weak","title":"RustDesk Client authentication bypass via session replay and weak hashing","severity":"critical","exploited":false,"published_at":"2026-03-05T16:16:19.56+00:00","url":"https://junglewise.ai/threats/cve-2026-30789-rustdesk-client-authentication-bypass-via-session-replay-and-weak"},{"cve":"CVE-2026-30783","cvss":9.8,"epss":0.0059,"slug":"cve-2026-30783-rustdesk-client-privilege-abuse-via-unauthenticated-strategy","title":"RustDesk Client privilege abuse via unauthenticated strategy injection","severity":"critical","exploited":false,"published_at":"2026-03-05T16:16:18.91+00:00","url":"https://junglewise.ai/threats/cve-2026-30783-rustdesk-client-privilege-abuse-via-unauthenticated-strategy"}],"high":7,"name":"Google Android","rank":12,"slug":"android","score":50,"vendor":{"name":"Google","slug":"google"},"critical":3,"max_cvss":9.8,"max_epss":0.0059,"exploited":1,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/android"},{"hub":true,"top":[{"cve":"CVE-2026-23392","cvss":7.8,"epss":0.0012,"slug":"cve-2026-23392-linux-kernel-netfilter-use-after-free-in-nf-tables-flowtable","title":"Linux Kernel netfilter use-after-free in nf_tables flowtable error path","severity":"high","exploited":false,"published_at":"2026-03-25T11:16:39.873+00:00","url":"https://junglewise.ai/threats/cve-2026-23392-linux-kernel-netfilter-use-after-free-in-nf-tables-flowtable"},{"cve":"CVE-2026-23391","cvss":7.8,"epss":0.0012,"slug":"cve-2026-23391-linux-kernel-netfilter-use-after-free-in-xt-ct-template-removal","title":"Linux Kernel netfilter use-after-free in xt_CT template removal","severity":"high","exploited":false,"published_at":"2026-03-25T11:16:39.707+00:00","url":"https://junglewise.ai/threats/cve-2026-23391-linux-kernel-netfilter-use-after-free-in-xt-ct-template-removal"},{"cve":"CVE-2026-23378","cvss":7.8,"epss":0.0013,"slug":"cve-2026-23378-linux-kernel-out-of-bounds-write-in-net-sched-act-ife","title":"Linux Kernel out-of-bounds write in net/sched act_ife","severity":"high","exploited":false,"published_at":"2026-03-25T11:16:37.643+00:00","url":"https://junglewise.ai/threats/cve-2026-23378-linux-kernel-out-of-bounds-write-in-net-sched-act-ife"}],"high":11,"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","rank":13,"slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","score":46,"vendor":{"name":"Siemens","slug":"siemens"},"critical":0,"max_cvss":7.8,"max_epss":0.0036,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},{"hub":true,"top":[{"cve":"CVE-2025-43510","cvss":7.8,"epss":0.003,"slug":"cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory","title":"Apple Multiple Products improper locking in shared memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43510-apple-multiple-products-improper-locking-in-shared-memory"},{"cve":"CVE-2025-43520","cvss":5.5,"epss":0.0027,"slug":"cve-2025-43520-apple-multiple-products-classic-buffer-overflow-in-kernel-memory","title":"Apple Multiple Products classic buffer overflow in kernel memory","severity":"critical","exploited":true,"published_at":"2026-03-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-43520-apple-multiple-products-classic-buffer-overflow-in-kernel-memory"},{"cve":"CVE-2026-28878","cvss":6.5,"slug":"cve-2026-28878-apple-multiple-os-privacy-issue-in-crash-reporter","title":"Apple multiple OS privacy issue in Crash Reporter","severity":"medium","exploited":false,"published_at":"2026-03-25T01:17:11.62+00:00","url":"https://junglewise.ai/threats/cve-2026-28878-apple-multiple-os-privacy-issue-in-crash-reporter"}],"high":0,"name":"Apple visionOS","rank":14,"slug":"visionos","score":43,"vendor":{"name":"Apple","slug":"apple"},"critical":2,"max_cvss":7.8,"max_epss":0.0048,"exploited":2,"vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/visionos"},{"hub":true,"top":[{"cve":"CVE-2026-33017","cvss":9.8,"epss":0.2465,"slug":"cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public","title":"Langflow unauthenticated remote code execution in build_public_tmp endpoint","severity":"critical","exploited":true,"published_at":"2026-03-20T05:16:15.55+00:00","url":"https://junglewise.ai/threats/cve-2026-33017-langflow-unauthenticated-remote-code-execution-in-build-public"},{"cve":"CVE-2026-33309","cvss":9.9,"epss":0.0105,"slug":"cve-2026-33309-langflow-path-traversal-and-arbitrary-file-write-in-v2-api","title":"Langflow path traversal and arbitrary file write in v2 API","severity":"critical","exploited":false,"published_at":"2026-03-19T17:46:43+00:00","url":"https://junglewise.ai/threats/cve-2026-33309-langflow-path-traversal-and-arbitrary-file-write-in-v2-api"},{"cve":"CVE-2026-33873","cvss":9.1,"epss":0.0007,"slug":"cve-2026-33873-langflow-authenticated-code-execution-in-agentic-assistant","title":"Langflow authenticated code execution in Agentic Assistant validation","severity":"critical","exploited":false,"published_at":"2026-03-26T18:31:36+00:00","url":"https://junglewise.ai/threats/cve-2026-33873-langflow-authenticated-code-execution-in-agentic-assistant"}],"high":5,"name":"Langflow","rank":15,"slug":"langflow","score":43,"vendor":{"name":"Langflow","slug":"langflow"},"critical":3,"max_cvss":9.9,"max_epss":0.2465,"exploited":1,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/langflow"},{"hub":true,"top":[{"cve":"CVE-2026-4688","cvss":10,"epss":0.0041,"slug":"cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability","title":"Mozilla Firefox and Thunderbird sandbox escape in Disability Access APIs","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:04.64+00:00","url":"https://junglewise.ai/threats/cve-2026-4688-mozilla-firefox-and-thunderbird-sandbox-escape-in-disability"},{"cve":"CVE-2026-4721","cvss":9.8,"epss":0.0043,"slug":"cve-2026-4721-mozilla-firefox-and-thunderbird-multiple-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird multiple memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:07.99+00:00","url":"https://junglewise.ai/threats/cve-2026-4721-mozilla-firefox-and-thunderbird-multiple-memory-safety-bugs"},{"cve":"CVE-2026-4720","cvss":9.8,"epss":0.0042,"slug":"cve-2026-4720-mozilla-firefox-and-thunderbird-memory-safety-bugs","title":"Mozilla Firefox and Thunderbird memory safety bugs","severity":"critical","exploited":false,"published_at":"2026-03-24T13:16:07.893+00:00","url":"https://junglewise.ai/threats/cve-2026-4720-mozilla-firefox-and-thunderbird-memory-safety-bugs"}],"high":3,"name":"Mozilla Thunderbird-Esr","rank":16,"slug":"thunderbird-esr","score":39,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":5,"max_cvss":10,"max_epss":0.0051,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/thunderbird-esr"},{"hub":true,"top":[{"cve":"CVE-2026-20131","cvss":10,"epss":0.0172,"slug":"cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce","title":"Cisco Secure Firewall Management Center deserialization RCE","severity":"critical","exploited":true,"published_at":"2026-03-19T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce"},{"cve":"CVE-2026-20079","cvss":10,"epss":0.8818,"slug":"cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web","title":"Cisco Secure Firewall Management Center auth bypass in web interface","severity":"critical","exploited":true,"published_at":"2026-03-04T18:16:24.23+00:00","url":"https://junglewise.ai/threats/cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web"},{"cve":"CVE-2026-20002","cvss":8.1,"epss":0.0035,"slug":"cve-2026-20002-cisco-secure-fmc-sql-injection-in-web-based-management-interface","title":"Cisco Secure FMC SQL injection in web-based management interface","severity":"high","exploited":false,"published_at":"2026-03-04T18:16:12.557+00:00","url":"https://junglewise.ai/threats/cve-2026-20002-cisco-secure-fmc-sql-injection-in-web-based-management-interface"}],"high":1,"name":"Cisco Secure Firewall Management Center","rank":17,"slug":"secure-firewall-management-center","score":37,"vendor":{"name":"Cisco","slug":"cisco"},"critical":2,"max_cvss":10,"max_epss":0.8818,"exploited":2,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/secure-firewall-management-center"},{"hub":true,"top":[{"cve":"CVE-2026-3909","cvss":8.8,"epss":0.0039,"slug":"cve-2026-3909-google-skia-out-of-bounds-write-in-google-chrome","title":"Google Skia out-of-bounds write in Google Chrome","severity":"critical","exploited":true,"published_at":"2026-03-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-3909-google-skia-out-of-bounds-write-in-google-chrome"},{"cve":"CVE-2026-3910","cvss":8.8,"epss":0.0082,"slug":"cve-2026-3910-google-chromium-v8-memory-corruption-in-javascript-engine","title":"Google Chromium V8 memory corruption in JavaScript engine","severity":"critical","exploited":true,"published_at":"2026-03-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-3910-google-chromium-v8-memory-corruption-in-javascript-engine"},{"cve":"CVE-2026-4447","cvss":8.8,"epss":0.0004,"slug":"cve-2026-4447-google-chrome-v8-inappropriate-implementation-code-execution","title":"Google Chrome V8 inappropriate implementation code execution","severity":"high","exploited":false,"published_at":"2026-03-20T02:16:37.52+00:00","url":"https://junglewise.ai/threats/cve-2026-4447-google-chrome-v8-inappropriate-implementation-code-execution"}],"high":1,"name":"Google Chrome","rank":18,"slug":"chrome","score":35,"vendor":{"name":"Google","slug":"google"},"critical":2,"max_cvss":8.8,"max_epss":0.0082,"exploited":2,"vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-20131","cvss":10,"epss":0.0172,"slug":"cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce","title":"Cisco Secure Firewall Management Center deserialization RCE","severity":"critical","exploited":true,"published_at":"2026-03-19T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce"},{"cve":"CVE-2026-20079","cvss":10,"epss":0.8818,"slug":"cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web","title":"Cisco Secure Firewall Management Center auth bypass in web interface","severity":"critical","exploited":true,"published_at":"2026-03-04T18:16:24.23+00:00","url":"https://junglewise.ai/threats/cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web"},{"cve":"CVE-2026-20058","cvss":5.8,"epss":0.0039,"slug":"cve-2026-20058-cisco-snort-3-vba-decompression-denial-of-service","title":"Cisco Snort 3 VBA decompression denial of service","severity":"medium","exploited":false,"published_at":"2026-03-04T18:16:20.643+00:00","url":"https://junglewise.ai/threats/cve-2026-20058-cisco-snort-3-vba-decompression-denial-of-service"}],"high":0,"name":"Cisco Secure Firewall Management Center (FMC)","rank":19,"slug":"secure-firewall-management-center-fmc","score":33,"vendor":{"name":"Cisco","slug":"cisco"},"critical":2,"max_cvss":10,"max_epss":0.8818,"exploited":2,"vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/secure-firewall-management-center-fmc"},{"hub":false,"top":[{"cve":"CVE-2026-20131","cvss":10,"epss":0.0172,"slug":"cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce","title":"Cisco Secure Firewall Management Center deserialization RCE","severity":"critical","exploited":true,"published_at":"2026-03-19T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-20131-cisco-secure-firewall-management-center-deserialization-rce"},{"cve":"CVE-2026-20079","cvss":10,"epss":0.8818,"slug":"cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web","title":"Cisco Secure Firewall Management Center auth bypass in web interface","severity":"critical","exploited":true,"published_at":"2026-03-04T18:16:24.23+00:00","url":"https://junglewise.ai/threats/cve-2026-20079-cisco-secure-firewall-management-center-auth-bypass-in-web"}],"high":0,"name":"Cisco Security Cloud Control","rank":20,"slug":"security-cloud-control","score":32,"vendor":{"name":"Cisco","slug":"cisco"},"critical":2,"max_cvss":10,"max_epss":0.8818,"exploited":2,"vulnerabilities":2},{"hub":true,"top":[{"cve":"CVE-2025-67038","cvss":9.8,"epss":0.0047,"slug":"cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module","title":"Lantronix EDS5000 OS command injection in HTTP RPC module","severity":"critical","exploited":true,"published_at":"2026-03-11T17:16:52.01+00:00","url":"https://junglewise.ai/threats/cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module"},{"cve":"CVE-2025-67035","cvss":9.8,"epss":0.0043,"slug":"cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages","title":"Lantronix EDS5000 OS command injection in SSH management pages","severity":"critical","exploited":false,"published_at":"2026-03-11T17:16:51.673+00:00","url":"https://junglewise.ai/threats/cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages"},{"cve":"CVE-2025-67037","cvss":8.8,"epss":0.0038,"slug":"cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter","title":"Lantronix EDS5000 OS command injection in tunnel parameter","severity":"high","exploited":false,"published_at":"2026-03-11T17:16:51.9+00:00","url":"https://junglewise.ai/threats/cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter"}],"high":3,"name":"Lantronix EDS5008","rank":21,"slug":"eds5008","score":31,"vendor":{"name":"Lantronix","slug":"lantronix"},"critical":2,"max_cvss":9.8,"max_epss":0.0049,"exploited":1,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/eds5008"},{"hub":true,"top":[{"cve":"CVE-2025-67038","cvss":9.8,"epss":0.0047,"slug":"cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module","title":"Lantronix EDS5000 OS command injection in HTTP RPC module","severity":"critical","exploited":true,"published_at":"2026-03-11T17:16:52.01+00:00","url":"https://junglewise.ai/threats/cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module"},{"cve":"CVE-2025-67035","cvss":9.8,"epss":0.0043,"slug":"cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages","title":"Lantronix EDS5000 OS command injection in SSH management pages","severity":"critical","exploited":false,"published_at":"2026-03-11T17:16:51.673+00:00","url":"https://junglewise.ai/threats/cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages"},{"cve":"CVE-2025-67037","cvss":8.8,"epss":0.0038,"slug":"cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter","title":"Lantronix EDS5000 OS command injection in tunnel parameter","severity":"high","exploited":false,"published_at":"2026-03-11T17:16:51.9+00:00","url":"https://junglewise.ai/threats/cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter"}],"high":3,"name":"Lantronix Eds5008 Firmware","rank":22,"slug":"eds5008-firmware","score":31,"vendor":{"name":"Lantronix","slug":"lantronix"},"critical":2,"max_cvss":9.8,"max_epss":0.0049,"exploited":1,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/eds5008-firmware"},{"hub":true,"top":[{"cve":"CVE-2025-67038","cvss":9.8,"epss":0.0047,"slug":"cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module","title":"Lantronix EDS5000 OS command injection in HTTP RPC module","severity":"critical","exploited":true,"published_at":"2026-03-11T17:16:52.01+00:00","url":"https://junglewise.ai/threats/cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module"},{"cve":"CVE-2025-67035","cvss":9.8,"epss":0.0043,"slug":"cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages","title":"Lantronix EDS5000 OS command injection in SSH management pages","severity":"critical","exploited":false,"published_at":"2026-03-11T17:16:51.673+00:00","url":"https://junglewise.ai/threats/cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages"},{"cve":"CVE-2025-67037","cvss":8.8,"epss":0.0038,"slug":"cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter","title":"Lantronix EDS5000 OS command injection in tunnel parameter","severity":"high","exploited":false,"published_at":"2026-03-11T17:16:51.9+00:00","url":"https://junglewise.ai/threats/cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter"}],"high":3,"name":"Lantronix EDS5016","rank":23,"slug":"eds5016","score":31,"vendor":{"name":"Lantronix","slug":"lantronix"},"critical":2,"max_cvss":9.8,"max_epss":0.0049,"exploited":1,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/eds5016"},{"hub":true,"top":[{"cve":"CVE-2025-67038","cvss":9.8,"epss":0.0047,"slug":"cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module","title":"Lantronix EDS5000 OS command injection in HTTP RPC module","severity":"critical","exploited":true,"published_at":"2026-03-11T17:16:52.01+00:00","url":"https://junglewise.ai/threats/cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module"},{"cve":"CVE-2025-67035","cvss":9.8,"epss":0.0043,"slug":"cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages","title":"Lantronix EDS5000 OS command injection in SSH management pages","severity":"critical","exploited":false,"published_at":"2026-03-11T17:16:51.673+00:00","url":"https://junglewise.ai/threats/cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages"},{"cve":"CVE-2025-67037","cvss":8.8,"epss":0.0038,"slug":"cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter","title":"Lantronix EDS5000 OS command injection in tunnel parameter","severity":"high","exploited":false,"published_at":"2026-03-11T17:16:51.9+00:00","url":"https://junglewise.ai/threats/cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter"}],"high":3,"name":"Lantronix Eds5016 Firmware","rank":24,"slug":"eds5016-firmware","score":31,"vendor":{"name":"Lantronix","slug":"lantronix"},"critical":2,"max_cvss":9.8,"max_epss":0.0049,"exploited":1,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/eds5016-firmware"},{"hub":true,"top":[{"cve":"CVE-2025-67038","cvss":9.8,"epss":0.0047,"slug":"cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module","title":"Lantronix EDS5000 OS command injection in HTTP RPC module","severity":"critical","exploited":true,"published_at":"2026-03-11T17:16:52.01+00:00","url":"https://junglewise.ai/threats/cve-2025-67038-lantronix-eds5000-os-command-injection-in-http-rpc-module"},{"cve":"CVE-2025-67035","cvss":9.8,"epss":0.0043,"slug":"cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages","title":"Lantronix EDS5000 OS command injection in SSH management pages","severity":"critical","exploited":false,"published_at":"2026-03-11T17:16:51.673+00:00","url":"https://junglewise.ai/threats/cve-2025-67035-lantronix-eds5000-os-command-injection-in-ssh-management-pages"},{"cve":"CVE-2025-67037","cvss":8.8,"epss":0.0038,"slug":"cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter","title":"Lantronix EDS5000 OS command injection in tunnel parameter","severity":"high","exploited":false,"published_at":"2026-03-11T17:16:51.9+00:00","url":"https://junglewise.ai/threats/cve-2025-67037-lantronix-eds5000-os-command-injection-in-tunnel-parameter"}],"high":3,"name":"Lantronix EDS5032","rank":25,"slug":"eds5032","score":31,"vendor":{"name":"Lantronix","slug":"lantronix"},"critical":2,"max_cvss":9.8,"max_epss":0.0049,"exploited":1,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/eds5032"}],"previous":null,"next":{"key":"2026-04","top":"Linux Kernel","period":{"end":"2026-04-30","start":"2026-04-01"},"totals":{"high":1331,"critical":379,"exploited":35,"technologies":2159,"vulnerabilities":3561},"url":"https://junglewise.ai/threats/monthly/2026-04"}}