Junglewise

Monthly report

Most vulnerable technologies in May 2026

Final report, published . It does not change.

In May 2026, Junglewise Threat Intelligence recorded 6,351 new vulnerabilities: 517 critical, 2,075 high and 26 exploited in the wild. The most vulnerable technology was Linux Kernel, with 913 vulnerabilities (28 critical), followed by Google Chrome (249) and Apple macOS (111).

New vulnerabilities
6,351
Critical
517
Exploited in the wild
26
Technologies affected
3,603

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Linux Kernel
Linux
9132817709.8
2Google Chrome
Google
24935309.8
3Apple macOS
Apple
11116509.6
4Microsoft Windows
Microsoft
51342110
5Apple iPadOS
Apple
7004208.8
6TOTOLINK A8000RU
TOTOLINK
2424009.8
7Openclaw
Openclaw
8122409.8
8Pip Open-Webui
Pip
6113109.1
9Apple visionOS
Apple
4802608.8
10Apple tvOS
Apple
4602708.8
11Apple watchOS
Apple
4302508.8
12Npm Vm2
Npm
21133010
13HPE Aruba Networking AOS-10
HPE Aruba Networking
2702708.8
14Thorsten phpMyFAQ
Thorsten
2841309.8
15Open ISES Tickets
Open ISES
4701208.2
16HPE Aruba Networking AOS-8
HPE Aruba Networking
2302307.5
17MB connect line mbCONNECT24
MB connect line
4001407.5
18MB connect line mymbCONNECT24
MB connect line
4001407.5
19F5 BIG-IP
F5
3201808.8
20F5 BIG-IP Access Policy Manager
F5
2811709.1
21Red Hat Self-service automation portal
Red Hat
12102010
22Concrete CMS
Concrete CMS
4401008.9
23Composer Concrete5/Concrete5
Composer
4401008.9
24Mozilla Firefox
Mozilla
393509.8
25Netatalk
Netatalk
3311309.9

Most affected vendors

  1. 1.Linux914 vulnerabilities, 28 critical, 0 exploited
  2. 2.Microsoft174 vulnerabilities, 27 critical, 7 exploited
  3. 3.Go212 vulnerabilities, 42 critical, 0 exploited
  4. 4.Npm215 vulnerabilities, 32 critical, 0 exploited
  5. 5.Pip191 vulnerabilities, 17 critical, 0 exploited
  6. 6.Google263 vulnerabilities, 4 critical, 0 exploited
  7. 7.Composer177 vulnerabilities, 13 critical, 0 exploited
  8. 8.Apple123 vulnerabilities, 1 critical, 0 exploited
  9. 9.Red Hat76 vulnerabilities, 18 critical, 0 exploited
  10. 10.Maven75 vulnerabilities, 11 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/monthly/2026-05.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in May 2026", https://junglewise.ai/threats/monthly/2026-05, 26 September 2026.