Monthly report
Most vulnerable technologies in May 2026
Final report, published . It does not change.
In May 2026, Junglewise Threat Intelligence recorded 6,351 new vulnerabilities: 517 critical, 2,075 high and 26 exploited in the wild. The most vulnerable technology was Linux Kernel, with 913 vulnerabilities (28 critical), followed by Google Chrome (249) and Apple macOS (111).
- New vulnerabilities
- 6,351
- Critical
- 517
- Exploited in the wild
- 26
- Technologies affected
- 3,603
Ranking
Most affected vendors
- 1.Linux914 vulnerabilities, 28 critical, 0 exploited
- 2.Microsoft174 vulnerabilities, 27 critical, 7 exploited
- 3.Go212 vulnerabilities, 42 critical, 0 exploited
- 4.Npm215 vulnerabilities, 32 critical, 0 exploited
- 5.Pip191 vulnerabilities, 17 critical, 0 exploited
- 6.Google263 vulnerabilities, 4 critical, 0 exploited
- 7.Composer177 vulnerabilities, 13 critical, 0 exploited
- 8.Apple123 vulnerabilities, 1 critical, 0 exploited
- 9.Red Hat76 vulnerabilities, 18 critical, 0 exploited
- 10.Maven75 vulnerabilities, 11 critical, 0 exploited
Most severe vulnerabilities
- CVE-2008-4250: Microsoft Windows buffer overflow in Server servicecriticalexploited in the wildCVSS 10EPSS 93.5%
- CVE-2026-20182: Cisco Catalyst SD-WAN authentication bypass in peering mechanismcriticalexploited in the wildCVSS 10EPSS 77.9%
- CVE-2026-34910: Ubiquiti UniFi OS command injection via improper input validationcriticalexploited in the wildCVSS 10EPSS 33.6%
- CVE-2026-34909: Ubiquiti UniFi OS path traversal in underlying system filescriticalexploited in the wildCVSS 10EPSS 0.9%
- CVE-2026-34908: Ubiquiti UniFi OS improper access controlcriticalexploited in the wildCVSS 10EPSS 0.9%
- CVE-2026-48172: LiteSpeed User-End cPanel Plugin privilege escalation to rootcriticalexploited in the wildCVSS 10EPSS 0.0%
- CVE-2026-42208: BerriAI LiteLLM SQL injection in Proxy API key verificationcriticalexploited in the wildCVSS 9.8EPSS 84.1%
- CVE-2026-9082: Drupal Drupal core SQL injection in database abstraction APIcriticalexploited in the wildCVSS 9.8EPSS 33.7%
- CVE-2026-0300: Palo Alto Networks PAN-OS buffer overflow in User-ID Authentication Portalcriticalexploited in the wildCVSS 9.8EPSS 14.4%
- CVE-2026-46817: Oracle E-Business Suite remote compromise in Oracle Paymentscriticalexploited in the wildCVSS 9.8EPSS 0.7%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/monthly/2026-05.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in May 2026", https://junglewise.ai/threats/monthly/2026-05, 26 September 2026.