Monthly report
Most vulnerable technologies in April 2026
Final report, published . It does not change.
In April 2026, Junglewise Threat Intelligence recorded 3,561 new vulnerabilities: 379 critical, 1,331 high and 35 exploited in the wild. The most vulnerable technology was Linux Kernel, with 300 vulnerabilities (20 critical, 2 exploited in the wild), followed by Openclaw (260) and Microsoft Windows (108).
- New vulnerabilities
- 3,561
- Critical
- 379
- Exploited in the wild
- 35
- Technologies affected
- 2,159
Ranking
Most affected vendors
- 1.Linux300 vulnerabilities, 20 critical, 2 exploited
- 2.Microsoft159 vulnerabilities, 21 critical, 11 exploited
- 3.Npm215 vulnerabilities, 21 critical, 0 exploited
- 4.Go145 vulnerabilities, 16 critical, 0 exploited
- 5.Openclaw260 vulnerabilities, 4 critical, 0 exploited
- 6.Google129 vulnerabilities, 7 critical, 1 exploited
- 7.Pip106 vulnerabilities, 16 critical, 0 exploited
- 8.Apple104 vulnerabilities, 4 critical, 1 exploited
- 9.Red Hat73 vulnerabilities, 11 critical, 0 exploited
- 10.Composer68 vulnerabilities, 8 critical, 0 exploited
Most severe vulnerabilities
- CVE-2025-32975: Quest KACE Systems Management Appliance authentication bypass in SSOcriticalexploited in the wildCVSS 10EPSS 46.5%
- CVE-2024-57726: SimpleHelp privilege escalation via missing authorization in API key creationcriticalexploited in the wildCVSS 9.9EPSS 46.0%
- CVE-2026-35616: Fortinet FortiClientEMS improper access control in APIcriticalexploited in the wildCVSS 9.8EPSS 88.9%
- CVE-2024-7399: Samsung MagicINFO 9 Server path traversalcriticalexploited in the wildCVSS 9.8EPSS 84.4%
- CVE-2026-41940: WebPros cPanel & WHM authentication bypass in login flowcriticalexploited in the wildCVSS 9.8EPSS 74.2%
- CVE-2026-1340: Ivanti Endpoint Manager Mobile code injectioncriticalexploited in the wildCVSS 9.8EPSS 65.7%
- CVE-2026-21643: Fortinet FortiClient EMS SQL injectioncriticalexploited in the wildCVSS 9.8EPSS 62.5%
- CVE-2026-39808: Fortinet FortiSandbox OS command injection in API endpointcriticalexploited in the wildCVSS 9.8EPSS 48.7%
- CVE-2026-39987: Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypasscriticalexploited in the wildCVSS 9.8EPSS 37.9%
- CVE-2026-33824: Microsoft Windows double free in IKE Extensioncriticalexploited in the wildCVSS 9.8EPSS 1.6%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/monthly/2026-04.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in April 2026", https://junglewise.ai/threats/monthly/2026-04, 26 September 2026.