Junglewise

Monthly report

Most vulnerable technologies in April 2026

Final report, published . It does not change.

In April 2026, Junglewise Threat Intelligence recorded 3,561 new vulnerabilities: 379 critical, 1,331 high and 35 exploited in the wild. The most vulnerable technology was Linux Kernel, with 300 vulnerabilities (20 critical, 2 exploited in the wild), followed by Openclaw (260) and Microsoft Windows (108).

New vulnerabilities
3,561
Critical
379
Exploited in the wild
35
Technologies affected
2,159

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Linux Kernel
Linux
3002014729.8
2Openclaw
Openclaw
26043209.6
3Microsoft Windows
Microsoft
10886259.8
4Google Chrome
Google
12377619.8
5Apple macOS
Apple
10246119.8
6Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
Siemens
4661909.8
7Dlink Di-8003
Dlink
2702707.5
8Dlink Di-8003 Firmware
Dlink
2702707.5
9Chamilo Lms
Chamilo
3131709.8
10Npm Flowise
Npm
2641509.9
11Mozilla Firefox
Mozilla
2141709.8
12Mozilla Thunderbird
Mozilla
2141709.8
13PraisonAI
Praison
188809.9
14Microsoft Windows 11
Microsoft
2011519.8
15Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Siemens
2931009.8
16Mozilla Firefox ESR
Mozilla
1631309.8
17Amazon AWS
Amazon
1311218.8
18Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Siemens
213709.8
19Cisco Catalyst SD-WAN Manager
Cisco
33037.5
20Composer Wwbn/Avideo
Composer
1837010
21MervinPraison PraisonAI Agents
MervinPraison
134609.9
22Endian-Firewall-Community
Endian
320608.8
23Tenda F451
Tenda
1401408.8
24Microsoft Windows 10
Microsoft
111819.8
25Npm Flowise-Components
Npm
123709.9

Most affected vendors

  1. 1.Linux300 vulnerabilities, 20 critical, 2 exploited
  2. 2.Microsoft159 vulnerabilities, 21 critical, 11 exploited
  3. 3.Npm215 vulnerabilities, 21 critical, 0 exploited
  4. 4.Go145 vulnerabilities, 16 critical, 0 exploited
  5. 5.Openclaw260 vulnerabilities, 4 critical, 0 exploited
  6. 6.Google129 vulnerabilities, 7 critical, 1 exploited
  7. 7.Pip106 vulnerabilities, 16 critical, 0 exploited
  8. 8.Apple104 vulnerabilities, 4 critical, 1 exploited
  9. 9.Red Hat73 vulnerabilities, 11 critical, 0 exploited
  10. 10.Composer68 vulnerabilities, 8 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/monthly/2026-04.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in April 2026", https://junglewise.ai/threats/monthly/2026-04, 26 September 2026.