{"schema_version":1,"title":"Most vulnerable technologies in May 2026","summary":"In May 2026, Junglewise Threat Intelligence recorded 6,351 new vulnerabilities: 517 critical, 2,075 high and 26 exploited in the wild. The most vulnerable technology was Linux Kernel, with 913 vulnerabilities (28 critical), followed by Google Chrome (249) and Apple macOS (111).","url":"https://junglewise.ai/threats/monthly/2026-05","json_url":"https://junglewise.ai/threats/monthly/2026-05.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/monthly/2026-05","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"month","period":{"end":"2026-05-31","start":"2026-05-01"},"totals":{"high":2075,"critical":517,"exploited":26,"technologies":3603,"vulnerabilities":6351},"notable":[{"cve":"CVE-2008-4250","cvss":10,"epss":0.9348,"slug":"cve-2008-4250-microsoft-windows-buffer-overflow-in-server-service","title":"Microsoft Windows buffer overflow in Server service","severity":"critical","exploited":true,"published_at":"2026-05-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2008-4250-microsoft-windows-buffer-overflow-in-server-service"},{"cve":"CVE-2026-20182","cvss":10,"epss":0.779,"slug":"cve-2026-20182-cisco-catalyst-sd-wan-authentication-bypass-in-peering-mechanism","title":"Cisco Catalyst SD-WAN authentication bypass in peering mechanism","severity":"critical","exploited":true,"published_at":"2026-05-14T17:16:19.387+00:00","url":"https://junglewise.ai/threats/cve-2026-20182-cisco-catalyst-sd-wan-authentication-bypass-in-peering-mechanism"},{"cve":"CVE-2026-34910","cvss":10,"epss":0.3362,"slug":"cve-2026-34910-ubiquiti-unifi-os-command-injection-via-improper-input-validation","title":"Ubiquiti UniFi OS command injection via improper input validation","severity":"critical","exploited":true,"published_at":"2026-05-22T02:16:34.527+00:00","url":"https://junglewise.ai/threats/cve-2026-34910-ubiquiti-unifi-os-command-injection-via-improper-input-validation"},{"cve":"CVE-2026-34909","cvss":10,"epss":0.009,"slug":"cve-2026-34909-ubiquiti-unifi-os-path-traversal-in-underlying-system-files","title":"Ubiquiti UniFi OS path traversal in underlying system files","severity":"critical","exploited":true,"published_at":"2026-05-22T02:16:34.39+00:00","url":"https://junglewise.ai/threats/cve-2026-34909-ubiquiti-unifi-os-path-traversal-in-underlying-system-files"},{"cve":"CVE-2026-34908","cvss":10,"epss":0.0086,"slug":"cve-2026-34908-ubiquiti-unifi-os-improper-access-control","title":"Ubiquiti UniFi OS improper access control","severity":"critical","exploited":true,"published_at":"2026-05-22T02:16:34.24+00:00","url":"https://junglewise.ai/threats/cve-2026-34908-ubiquiti-unifi-os-improper-access-control"},{"cve":"CVE-2026-48172","cvss":10,"epss":0.0001,"slug":"cve-2026-48172-litespeed-user-end-cpanel-plugin-privilege-escalation-to-root","title":"LiteSpeed User-End cPanel Plugin privilege escalation to root","severity":"critical","exploited":true,"published_at":"2026-05-21T02:16:33.76+00:00","url":"https://junglewise.ai/threats/cve-2026-48172-litespeed-user-end-cpanel-plugin-privilege-escalation-to-root"},{"cve":"CVE-2026-42208","cvss":9.8,"epss":0.8411,"slug":"cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification","title":"BerriAI LiteLLM SQL injection in Proxy API key verification","severity":"critical","exploited":true,"published_at":"2026-05-08T04:16:19.923+00:00","url":"https://junglewise.ai/threats/cve-2026-42208-berriai-litellm-sql-injection-in-proxy-api-key-verification"},{"cve":"CVE-2026-9082","cvss":9.8,"epss":0.3367,"slug":"cve-2026-9082-drupal-drupal-core-sql-injection-in-database-abstraction-api","title":"Drupal Drupal core SQL injection in database abstraction API","severity":"critical","exploited":true,"published_at":"2026-05-20T20:16:41.23+00:00","url":"https://junglewise.ai/threats/cve-2026-9082-drupal-drupal-core-sql-injection-in-database-abstraction-api"},{"cve":"CVE-2026-0300","cvss":9.8,"epss":0.1443,"slug":"cve-2026-0300-palo-alto-networks-pan-os-buffer-overflow-in-user-id","title":"Palo Alto Networks PAN-OS buffer overflow in User-ID Authentication Portal","severity":"critical","exploited":true,"published_at":"2026-05-06T19:16:35.73+00:00","url":"https://junglewise.ai/threats/cve-2026-0300-palo-alto-networks-pan-os-buffer-overflow-in-user-id"},{"cve":"CVE-2026-46817","cvss":9.8,"epss":0.0068,"slug":"cve-2026-46817-oracle-e-business-suite-remote-compromise-in-oracle-payments","title":"Oracle E-Business Suite remote compromise in Oracle Payments","severity":"critical","exploited":true,"published_at":"2026-05-28T21:16:31.503+00:00","url":"https://junglewise.ai/threats/cve-2026-46817-oracle-e-business-suite-remote-compromise-in-oracle-payments"}],"vendors":[{"hub":true,"high":177,"name":"Linux","rank":1,"slug":"linux","critical":28,"exploited":0,"vulnerabilities":914,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":112,"name":"Microsoft","rank":2,"slug":"microsoft","critical":27,"exploited":7,"vulnerabilities":174,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":79,"name":"Go","rank":3,"slug":"go","critical":42,"exploited":0,"vulnerabilities":212,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":83,"name":"Npm","rank":4,"slug":"npm","critical":32,"exploited":0,"vulnerabilities":215,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":85,"name":"Pip","rank":5,"slug":"pip","critical":17,"exploited":0,"vulnerabilities":191,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":57,"name":"Google","rank":6,"slug":"google","critical":4,"exploited":0,"vulnerabilities":263,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":61,"name":"Composer","rank":7,"slug":"composer","critical":13,"exploited":0,"vulnerabilities":177,"url":"https://junglewise.ai/threats/vendors/composer"},{"hub":true,"high":71,"name":"Apple","rank":8,"slug":"apple","critical":1,"exploited":0,"vulnerabilities":123,"url":"https://junglewise.ai/threats/vendors/apple"},{"hub":true,"high":37,"name":"Red Hat","rank":9,"slug":"red-hat","critical":18,"exploited":0,"vulnerabilities":76,"url":"https://junglewise.ai/threats/vendors/red-hat"},{"hub":true,"high":29,"name":"Maven","rank":10,"slug":"maven","critical":11,"exploited":0,"vulnerabilities":75,"url":"https://junglewise.ai/threats/vendors/maven"}],"generated_at":"2026-09-26T09:24:00.138874+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-43465","cvss":9.8,"epss":0.0008,"slug":"cve-2026-43465-linux-kernel-mlx5e-reference-counting-error-in-xdp-multi-buf-rx","title":"Linux Kernel mlx5e reference counting error in XDP multi-buf RX","severity":"critical","exploited":false,"published_at":"2026-05-08T15:16:59.41+00:00","url":"https://junglewise.ai/threats/cve-2026-43465-linux-kernel-mlx5e-reference-counting-error-in-xdp-multi-buf-rx"},{"cve":"CVE-2026-43414","cvss":9.8,"epss":0.0038,"slug":"cve-2026-43414-linux-kernel-qla2xxx-double-free-in-qla24xx-els-dcmd-iocb","title":"Linux Kernel qla2xxx double free in qla24xx_els_dcmd_iocb","severity":"critical","exploited":false,"published_at":"2026-05-08T15:16:53.353+00:00","url":"https://junglewise.ai/threats/cve-2026-43414-linux-kernel-qla2xxx-double-free-in-qla24xx-els-dcmd-iocb"},{"cve":"CVE-2026-43402","cvss":9.8,"epss":0.0005,"slug":"cve-2026-43402-linux-kernel-use-after-free-in-kthread-exit-paths","title":"Linux Kernel use-after-free in kthread exit paths","severity":"critical","exploited":false,"published_at":"2026-05-08T15:16:51.67+00:00","url":"https://junglewise.ai/threats/cve-2026-43402-linux-kernel-use-after-free-in-kthread-exit-paths"}],"high":177,"name":"Linux Kernel","rank":1,"slug":"kernel","score":1407,"vendor":{"name":"Linux","slug":"linux"},"critical":28,"max_cvss":9.8,"max_epss":0.0118,"exploited":0,"vulnerabilities":913,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-8580","cvss":9.6,"epss":0.0007,"slug":"cve-2026-8580-google-chrome-use-after-free-in-mojo","title":"Google Chrome use after free in Mojo","severity":"critical","exploited":false,"published_at":"2026-05-14T20:17:20.367+00:00","url":"https://junglewise.ai/threats/cve-2026-8580-google-chrome-use-after-free-in-mojo"},{"cve":"CVE-2026-8511","cvss":9.6,"epss":0.0007,"slug":"cve-2026-8511-google-chrome-use-after-free-in-ui","title":"Google Chrome use after free in UI","severity":"critical","exploited":false,"published_at":"2026-05-14T20:17:11.707+00:00","url":"https://junglewise.ai/threats/cve-2026-8511-google-chrome-use-after-free-in-ui"},{"cve":"CVE-2026-7910","cvss":9.6,"slug":"cve-2026-7910-google-chrome-use-after-free-in-views","title":"Google Chrome use after free in Views","severity":"critical","exploited":false,"published_at":"2026-05-06T19:16:39.287+00:00","url":"https://junglewise.ai/threats/cve-2026-7910-google-chrome-use-after-free-in-views"}],"high":53,"name":"Google Chrome","rank":2,"slug":"chrome","score":370,"vendor":{"name":"Google","slug":"google"},"critical":3,"max_cvss":9.8,"max_epss":0.0011,"exploited":0,"vulnerabilities":249,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-7910","cvss":9.6,"slug":"cve-2026-7910-google-chrome-use-after-free-in-views","title":"Google Chrome use after free in Views","severity":"critical","exploited":false,"published_at":"2026-05-06T19:16:39.287+00:00","url":"https://junglewise.ai/threats/cve-2026-7910-google-chrome-use-after-free-in-views"},{"cve":"CVE-2026-8587","cvss":8.8,"epss":0.0002,"slug":"cve-2026-8587-google-chrome-use-after-free-in-extensions-on-mac","title":"Google Chrome use after free in Extensions on Mac","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:21.083+00:00","url":"https://junglewise.ai/threats/cve-2026-8587-google-chrome-use-after-free-in-extensions-on-mac"},{"cve":"CVE-2026-8522","cvss":8.8,"epss":0.0008,"slug":"cve-2026-8522-google-chrome-use-after-free-in-downloads-on-macos","title":"Google Chrome use after free in Downloads on macOS","severity":"high","exploited":false,"published_at":"2026-05-14T20:17:12.973+00:00","url":"https://junglewise.ai/threats/cve-2026-8522-google-chrome-use-after-free-in-downloads-on-macos"}],"high":65,"name":"Apple macOS","rank":3,"slug":"macos-tahoe","score":246,"vendor":{"name":"Apple","slug":"apple"},"critical":1,"max_cvss":9.6,"max_epss":0.0118,"exploited":0,"vulnerabilities":111,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2008-4250","cvss":10,"epss":0.9348,"slug":"cve-2008-4250-microsoft-windows-buffer-overflow-in-server-service","title":"Microsoft Windows buffer overflow in Server service","severity":"critical","exploited":true,"published_at":"2026-05-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2008-4250-microsoft-windows-buffer-overflow-in-server-service"},{"cve":"CVE-2026-41089","cvss":9.8,"slug":"cve-2026-41089-microsoft-windows-stack-based-buffer-overflow-in-netlogon","title":"Microsoft Windows stack-based buffer overflow in Netlogon","severity":"critical","exploited":false,"published_at":"2026-05-12T18:17:20.72+00:00","url":"https://junglewise.ai/threats/cve-2026-41089-microsoft-windows-stack-based-buffer-overflow-in-netlogon"},{"cve":"CVE-2026-7910","cvss":9.6,"slug":"cve-2026-7910-google-chrome-use-after-free-in-views","title":"Google Chrome use after free in Views","severity":"critical","exploited":false,"published_at":"2026-05-06T19:16:39.287+00:00","url":"https://junglewise.ai/threats/cve-2026-7910-google-chrome-use-after-free-in-views"}],"high":42,"name":"Microsoft Windows","rank":4,"slug":"windows-","score":160,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":3,"max_cvss":10,"max_epss":0.9348,"exploited":1,"vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2026-28995","cvss":8.8,"epss":0.0015,"slug":"cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents","title":"A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:59.417+00:00","url":"https://junglewise.ai/threats/cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents"},{"cve":"CVE-2026-28947","cvss":8.8,"epss":0.0031,"slug":"cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management","title":"Apple Safari and OS use-after-free in memory management","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:55.863+00:00","url":"https://junglewise.ai/threats/cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management"},{"cve":"CVE-2026-28907","cvss":8.1,"slug":"cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass","title":"Apple Multiple Operating Systems Content Security Policy bypass","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:53.503+00:00","url":"https://junglewise.ai/threats/cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass"}],"high":42,"name":"Apple iPadOS","rank":5,"slug":"ipados","score":154,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":8.8,"max_epss":0.0064,"exploited":0,"vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/ipados"},{"hub":true,"top":[{"cve":"CVE-2026-9478","cvss":9.8,"epss":0.0089,"slug":"cve-2026-9478-totolink-a8000ru-os-command-injection-in-setparentalrules","title":"Totolink A8000RU OS command injection in setParentalRules","severity":"critical","exploited":false,"published_at":"2026-05-25T18:16:32.85+00:00","url":"https://junglewise.ai/threats/cve-2026-9478-totolink-a8000ru-os-command-injection-in-setparentalrules"},{"cve":"CVE-2026-9477","cvss":9.8,"epss":0.0089,"slug":"cve-2026-9477-totolink-a8000ru-command-injection-in-setaccessdevicecfg","title":"Totolink A8000RU command injection in setAccessDeviceCfg","severity":"critical","exploited":false,"published_at":"2026-05-25T18:16:31.903+00:00","url":"https://junglewise.ai/threats/cve-2026-9477-totolink-a8000ru-command-injection-in-setaccessdevicecfg"},{"cve":"CVE-2026-9476","cvss":9.8,"epss":0.0089,"slug":"cve-2026-9476-totolink-a8000ru-command-injection-in-setpasswordcfg","title":"Totolink A8000RU command injection in setPasswordCfg","severity":"critical","exploited":false,"published_at":"2026-05-25T17:16:47.663+00:00","url":"https://junglewise.ai/threats/cve-2026-9476-totolink-a8000ru-command-injection-in-setpasswordcfg"}],"high":0,"name":"TOTOLINK A8000RU","rank":6,"slug":"a8000ru","score":144,"vendor":{"name":"TOTOLINK","slug":"totolink"},"critical":24,"max_cvss":9.8,"max_epss":0.0094,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/a8000ru"},{"hub":true,"top":[{"cvss":9.8,"slug":"openclaw-authentication-bypass-in-feishu-webhook-validation-5fe7b465","title":"OpenClaw authentication bypass in Feishu webhook validation","severity":"critical","exploited":false,"published_at":"2026-05-06T21:31:42+00:00","url":"https://junglewise.ai/threats/openclaw-authentication-bypass-in-feishu-webhook-validation-5fe7b465"},{"cve":"CVE-2026-44112","cvss":9.6,"epss":0.0039,"slug":"cve-2026-44112-openclaw-openclaw-toctou-race-condition-in-openshell-fs-bridge","title":"OpenClaw TOCTOU race condition in OpenShell sandbox filesystem writes","severity":"critical","exploited":false,"published_at":"2026-05-06T20:16:35.057+00:00","url":"https://junglewise.ai/threats/cve-2026-44112-openclaw-openclaw-toctou-race-condition-in-openshell-fs-bridge"},{"cve":"CVE-2026-35674","cvss":8.8,"epss":0.0045,"slug":"cve-2026-35674-openclaw-scope-bypass-in-gateway-chat-send-route","title":"OpenClaw scope bypass in Gateway chat.send route","severity":"high","exploited":false,"published_at":"2026-05-29T16:16:26.377+00:00","url":"https://junglewise.ai/threats/cve-2026-35674-openclaw-scope-bypass-in-gateway-chat-send-route"}],"high":24,"name":"Openclaw","rank":7,"slug":"openclaw","score":139,"vendor":{"name":"Openclaw","slug":"openclaw"},"critical":2,"max_cvss":9.8,"max_epss":0.0123,"exploited":0,"vulnerabilities":81,"url":"https://junglewise.ai/threats/technologies/openclaw"},{"hub":true,"top":[{"cve":"CVE-2026-44551","cvss":9.1,"epss":0.0163,"slug":"cve-2026-44551-open-webui-ldap-authentication-bypass-via-empty-password","title":"Open WebUI LDAP authentication bypass via empty password","severity":"critical","exploited":false,"published_at":"2026-05-15T20:16:46.437+00:00","url":"https://junglewise.ai/threats/cve-2026-44551-open-webui-ldap-authentication-bypass-via-empty-password"},{"cve":"CVE-2026-45672","cvss":8.8,"slug":"cve-2026-45672-open-webui-arbitrary-code-execution-via-feature-gate-bypass","title":"Open WebUI arbitrary code execution via feature gate bypass","severity":"high","exploited":false,"published_at":"2026-05-15T21:16:38.51+00:00","url":"https://junglewise.ai/threats/cve-2026-45672-open-webui-arbitrary-code-execution-via-feature-gate-bypass"},{"cve":"CVE-2026-45315","cvss":8.7,"epss":0.0002,"slug":"cve-2026-45315-open-webui-stored-xss-in-audio-transcription-upload","title":"Open WebUI stored XSS in audio transcription upload","severity":"high","exploited":false,"published_at":"2026-05-15T22:16:54.25+00:00","url":"https://junglewise.ai/threats/cve-2026-45315-open-webui-stored-xss-in-audio-transcription-upload"}],"high":31,"name":"Pip Open-Webui","rank":8,"slug":"open-webui","score":128,"vendor":{"name":"Pip","slug":"pip"},"critical":1,"max_cvss":9.1,"max_epss":0.0163,"exploited":0,"vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"hub":true,"top":[{"cve":"CVE-2026-28995","cvss":8.8,"epss":0.0015,"slug":"cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents","title":"A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:59.417+00:00","url":"https://junglewise.ai/threats/cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents"},{"cve":"CVE-2026-28947","cvss":8.8,"epss":0.0031,"slug":"cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management","title":"Apple Safari and OS use-after-free in memory management","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:55.863+00:00","url":"https://junglewise.ai/threats/cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management"},{"cve":"CVE-2026-28907","cvss":8.1,"slug":"cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass","title":"Apple Multiple Operating Systems Content Security Policy bypass","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:53.503+00:00","url":"https://junglewise.ai/threats/cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass"}],"high":26,"name":"Apple visionOS","rank":9,"slug":"visionos","score":100,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":8.8,"max_epss":0.0064,"exploited":0,"vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/visionos"},{"hub":true,"top":[{"cve":"CVE-2026-28995","cvss":8.8,"epss":0.0015,"slug":"cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents","title":"A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:59.417+00:00","url":"https://junglewise.ai/threats/cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents"},{"cve":"CVE-2026-28947","cvss":8.8,"epss":0.0031,"slug":"cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management","title":"Apple Safari and OS use-after-free in memory management","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:55.863+00:00","url":"https://junglewise.ai/threats/cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management"},{"cve":"CVE-2026-28907","cvss":8.1,"slug":"cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass","title":"Apple Multiple Operating Systems Content Security Policy bypass","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:53.503+00:00","url":"https://junglewise.ai/threats/cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass"}],"high":27,"name":"Apple tvOS","rank":10,"slug":"tvos","score":100,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":8.8,"max_epss":0.0064,"exploited":0,"vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/tvos"},{"hub":true,"top":[{"cve":"CVE-2026-28995","cvss":8.8,"epss":0.0015,"slug":"cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents","title":"A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:59.417+00:00","url":"https://junglewise.ai/threats/cve-2026-28995-apple-multiple-operating-systems-sandbox-escape-in-app-intents"},{"cve":"CVE-2026-28947","cvss":8.8,"epss":0.0031,"slug":"cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management","title":"Apple Safari and OS use-after-free in memory management","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:55.863+00:00","url":"https://junglewise.ai/threats/cve-2026-28947-apple-safari-and-os-use-after-free-in-memory-management"},{"cve":"CVE-2026-28907","cvss":8.1,"slug":"cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass","title":"Apple Multiple Operating Systems Content Security Policy bypass","severity":"high","exploited":false,"published_at":"2026-05-11T21:18:53.503+00:00","url":"https://junglewise.ai/threats/cve-2026-28907-apple-multiple-operating-systems-content-security-policy-bypass"}],"high":25,"name":"Apple watchOS","rank":11,"slug":"watchos","score":93,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":8.8,"max_epss":0.0064,"exploited":0,"vulnerabilities":43,"url":"https://junglewise.ai/threats/technologies/watchos"},{"hub":true,"top":[{"cve":"CVE-2026-44006","cvss":10,"epss":0.0077,"slug":"cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access","title":"patriksimek vm2 sandbox escape via arbitrary prototype access","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.387+00:00","url":"https://junglewise.ai/threats/cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access"},{"cve":"CVE-2026-44005","cvss":10,"epss":0.0083,"slug":"cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation","title":"patriksimek vm2 sandbox escape via host prototype mutation","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.257+00:00","url":"https://junglewise.ai/threats/cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation"},{"cve":"CVE-2026-43997","cvss":10,"epss":0.0077,"slug":"cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage","title":"patriksimek vm2 sandbox escape via host object leakage","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:16.177+00:00","url":"https://junglewise.ai/threats/cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage"}],"high":3,"name":"Npm Vm2","rank":12,"slug":"vm2","score":92,"vendor":{"name":"Npm","slug":"npm"},"critical":13,"max_cvss":10,"max_epss":0.0119,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/vm2"},{"hub":true,"top":[{"cve":"CVE-2026-23819","cvss":8.8,"slug":"cve-2026-23819-hpe-aruba-aos-cross-site-scripting-in-web-management-interface","title":"HPE Aruba AOS Cross-Site Scripting in Web Management Interface","severity":"high","exploited":false,"published_at":"2026-05-12T19:16:28.603+00:00","url":"https://junglewise.ai/threats/cve-2026-23819-hpe-aruba-aos-cross-site-scripting-in-web-management-interface"},{"cve":"CVE-2026-23827","cvss":7.5,"slug":"cve-2026-23827-hpe-aruba-networking-aos-heap-overflow-in-network-management","title":"HPE Aruba Networking AOS heap overflow in Network management service","severity":"high","exploited":false,"published_at":"2026-05-12T20:16:31.797+00:00","url":"https://junglewise.ai/threats/cve-2026-23827-hpe-aruba-networking-aos-heap-overflow-in-network-management"},{"cve":"CVE-2026-23825","cvss":7.5,"slug":"cve-2026-23825-hpe-aruba-networking-aos-improper-input-validation-in-protocol","title":"HPE Aruba Networking AOS improper input validation in protocol-handling component","severity":"high","exploited":false,"published_at":"2026-05-12T20:16:31.573+00:00","url":"https://junglewise.ai/threats/cve-2026-23825-hpe-aruba-networking-aos-improper-input-validation-in-protocol"}],"high":27,"name":"HPE Aruba Networking AOS-10","rank":13,"slug":"aos-10","score":81,"vendor":{"name":"HPE Aruba Networking","slug":"hpe-aruba-networking"},"critical":0,"max_cvss":8.8,"max_epss":0.001,"exploited":0,"vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/aos-10"},{"hub":true,"top":[{"cvss":9.8,"slug":"phpmyfaq-sql-injection-in-builtincaptcha-via-user-agent-header-23e44a8e","title":"phpMyFAQ SQL injection in BuiltinCaptcha via User-Agent header","severity":"critical","exploited":false,"published_at":"2026-05-15T21:31:32+00:00","url":"https://junglewise.ai/threats/phpmyfaq-sql-injection-in-builtincaptcha-via-user-agent-header-23e44a8e"},{"cve":"CVE-2026-46364","cvss":9.8,"epss":0.0007,"slug":"cve-2026-46364-phpmyfaq-sql-injection-in-builtincaptcha-via-user-agent-header","title":"phpMyFAQ SQL injection in BuiltinCaptcha via User-Agent header","severity":"critical","exploited":false,"published_at":"2026-05-15T19:17:03.75+00:00","url":"https://junglewise.ai/threats/cve-2026-46364-phpmyfaq-sql-injection-in-builtincaptcha-via-user-agent-header"},{"cvss":9.1,"slug":"phpmyfaq-2fa-bypass-via-unauthenticated-brute-force-in-admin-check-7a3aa01c","title":"phpMyFAQ 2FA bypass via unauthenticated brute-force in admin check endpoint","severity":"critical","exploited":false,"published_at":"2026-05-15T21:31:32+00:00","url":"https://junglewise.ai/threats/phpmyfaq-2fa-bypass-via-unauthenticated-brute-force-in-admin-check-7a3aa01c"}],"high":13,"name":"Thorsten phpMyFAQ","rank":14,"slug":"phpmyfaq","score":74,"vendor":{"name":"Thorsten","slug":"thorsten"},"critical":4,"max_cvss":9.8,"max_epss":0.0015,"exploited":0,"vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/phpmyfaq"},{"hub":true,"top":[{"cve":"CVE-2026-48235","cvss":8.2,"slug":"cve-2026-48235-open-ises-tickets-sql-injection-in-incs-remotes-inc-php","title":"Open ISES Tickets SQL injection in incs/remotes.inc.php","severity":"high","exploited":false,"published_at":"2026-05-21T18:16:20.31+00:00","url":"https://junglewise.ai/threats/cve-2026-48235-open-ises-tickets-sql-injection-in-incs-remotes-inc-php"},{"cve":"CVE-2026-48242","cvss":8.1,"slug":"cve-2026-48242-open-ises-tickets-hardcoded-mysql-credentials-in-import-mdb-php","title":"Open ISES Tickets hardcoded MySQL credentials in import_mdb.php","severity":"high","exploited":false,"published_at":"2026-05-21T18:16:21.22+00:00","url":"https://junglewise.ai/threats/cve-2026-48242-open-ises-tickets-hardcoded-mysql-credentials-in-import-mdb-php"},{"cve":"CVE-2026-48241","cvss":8.1,"slug":"cve-2026-48241-open-ises-tickets-hardcoded-mysql-credentials-in-loader-php","title":"Open ISES Tickets hardcoded MySQL credentials in loader.php","severity":"high","exploited":false,"published_at":"2026-05-21T18:16:21.07+00:00","url":"https://junglewise.ai/threats/cve-2026-48241-open-ises-tickets-hardcoded-mysql-credentials-in-loader-php"}],"high":12,"name":"Open ISES Tickets","rank":15,"slug":"tickets","score":71,"vendor":{"name":"Open ISES","slug":"open-ises"},"critical":0,"max_cvss":8.2,"max_epss":null,"exploited":0,"vulnerabilities":47,"url":"https://junglewise.ai/threats/technologies/tickets"},{"hub":true,"top":[{"cve":"CVE-2026-23827","cvss":7.5,"slug":"cve-2026-23827-hpe-aruba-networking-aos-heap-overflow-in-network-management","title":"HPE Aruba Networking AOS heap overflow in Network management service","severity":"high","exploited":false,"published_at":"2026-05-12T20:16:31.797+00:00","url":"https://junglewise.ai/threats/cve-2026-23827-hpe-aruba-networking-aos-heap-overflow-in-network-management"},{"cve":"CVE-2026-23825","cvss":7.5,"slug":"cve-2026-23825-hpe-aruba-networking-aos-improper-input-validation-in-protocol","title":"HPE Aruba Networking AOS improper input validation in protocol-handling component","severity":"high","exploited":false,"published_at":"2026-05-12T20:16:31.573+00:00","url":"https://junglewise.ai/threats/cve-2026-23825-hpe-aruba-networking-aos-improper-input-validation-in-protocol"},{"cve":"CVE-2026-23824","cvss":7.5,"slug":"cve-2026-23824-hpe-aruba-aos-denial-of-service-in-protocol-handling-component","title":"HPE Aruba AOS denial of service in protocol-handling component","severity":"high","exploited":false,"published_at":"2026-05-12T20:16:31.463+00:00","url":"https://junglewise.ai/threats/cve-2026-23824-hpe-aruba-aos-denial-of-service-in-protocol-handling-component"}],"high":23,"name":"HPE Aruba Networking AOS-8","rank":16,"slug":"aos-8","score":69,"vendor":{"name":"HPE Aruba Networking","slug":"hpe-aruba-networking"},"critical":0,"max_cvss":7.5,"max_epss":0.001,"exploited":0,"vulnerabilities":23,"url":"https://junglewise.ai/threats/technologies/aos-8"},{"hub":true,"top":[{"cve":"CVE-2026-40850","cvss":7.5,"slug":"cve-2026-40850-mb-connect-line-mbconnect24-sql-injection-in-getaccountdata","title":"MB connect line mbCONNECT24 SQL injection in getAccountData","severity":"high","exploited":false,"published_at":"2026-05-27T09:16:31.547+00:00","url":"https://junglewise.ai/threats/cve-2026-40850-mb-connect-line-mbconnect24-sql-injection-in-getaccountdata"},{"cve":"CVE-2026-40819","cvss":7.5,"slug":"cve-2026-40819-mb-connect-line-mbconnect24-sql-injection-in-sync-data24-task","title":"MB connect line mbCONNECT24 SQL injection in sync_data24 task","severity":"high","exploited":false,"published_at":"2026-05-27T08:16:42.507+00:00","url":"https://junglewise.ai/threats/cve-2026-40819-mb-connect-line-mbconnect24-sql-injection-in-sync-data24-task"},{"cve":"CVE-2026-40818","cvss":7.5,"slug":"cve-2026-40818-mb-connect-line-mbconnect24-sql-injection-in-mb24confi-getdevice","title":"MB connect line mbCONNECT24 SQL injection in _mb24confi_getDevice","severity":"high","exploited":false,"published_at":"2026-05-27T08:16:42.353+00:00","url":"https://junglewise.ai/threats/cve-2026-40818-mb-connect-line-mbconnect24-sql-injection-in-mb24confi-getdevice"}],"high":14,"name":"MB connect line mbCONNECT24","rank":17,"slug":"mbconnect24","score":68,"vendor":{"name":"MB connect line","slug":"mb-connect-line"},"critical":0,"max_cvss":7.5,"max_epss":null,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/mbconnect24"},{"hub":true,"top":[{"cve":"CVE-2026-40850","cvss":7.5,"slug":"cve-2026-40850-mb-connect-line-mbconnect24-sql-injection-in-getaccountdata","title":"MB connect line mbCONNECT24 SQL injection in getAccountData","severity":"high","exploited":false,"published_at":"2026-05-27T09:16:31.547+00:00","url":"https://junglewise.ai/threats/cve-2026-40850-mb-connect-line-mbconnect24-sql-injection-in-getaccountdata"},{"cve":"CVE-2026-40819","cvss":7.5,"slug":"cve-2026-40819-mb-connect-line-mbconnect24-sql-injection-in-sync-data24-task","title":"MB connect line mbCONNECT24 SQL injection in sync_data24 task","severity":"high","exploited":false,"published_at":"2026-05-27T08:16:42.507+00:00","url":"https://junglewise.ai/threats/cve-2026-40819-mb-connect-line-mbconnect24-sql-injection-in-sync-data24-task"},{"cve":"CVE-2026-40818","cvss":7.5,"slug":"cve-2026-40818-mb-connect-line-mbconnect24-sql-injection-in-mb24confi-getdevice","title":"MB connect line mbCONNECT24 SQL injection in _mb24confi_getDevice","severity":"high","exploited":false,"published_at":"2026-05-27T08:16:42.353+00:00","url":"https://junglewise.ai/threats/cve-2026-40818-mb-connect-line-mbconnect24-sql-injection-in-mb24confi-getdevice"}],"high":14,"name":"MB connect line mymbCONNECT24","rank":18,"slug":"mymbconnect24","score":68,"vendor":{"name":"MB connect line","slug":"mb-connect-line"},"critical":0,"max_cvss":7.5,"max_epss":null,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/mymbconnect24"},{"hub":true,"top":[{"cve":"CVE-2026-41957","cvss":8.8,"epss":0.005,"slug":"cve-2026-41957-f5-big-ip-and-big-iq-rce-in-configuration-utility","title":"F5 BIG-IP and BIG-IQ RCE in Configuration utility","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:45.867+00:00","url":"https://junglewise.ai/threats/cve-2026-41957-f5-big-ip-and-big-iq-rce-in-configuration-utility"},{"cve":"CVE-2026-42930","cvss":8.7,"epss":0.0051,"slug":"cve-2026-42930-f5-big-ip-appliance-mode-restriction-bypass-via-path-traversal","title":"F5 BIG-IP Appliance mode restriction bypass via path traversal","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:49.777+00:00","url":"https://junglewise.ai/threats/cve-2026-42930-f5-big-ip-appliance-mode-restriction-bypass-via-path-traversal"},{"cve":"CVE-2026-42924","cvss":8.7,"epss":0.0025,"slug":"cve-2026-42924-f5-big-ip-privilege-escalation-in-icontrol-soap-via-snmp","title":"F5 BIG-IP privilege escalation in iControl SOAP via SNMP configuration","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:49.517+00:00","url":"https://junglewise.ai/threats/cve-2026-42924-f5-big-ip-privilege-escalation-in-icontrol-soap-via-snmp"}],"high":18,"name":"F5 BIG-IP","rank":19,"slug":"big-ip","score":68,"vendor":{"name":"F5","slug":"f5"},"critical":0,"max_cvss":8.8,"max_epss":0.0089,"exploited":0,"vulnerabilities":32,"url":"https://junglewise.ai/threats/technologies/big-ip"},{"hub":true,"top":[{"cve":"CVE-2026-41225","cvss":9.1,"epss":0.0027,"slug":"cve-2026-41225-f5-big-ip-arbitrary-command-execution-in-icontrol-rest","title":"F5 BIG-IP arbitrary command execution in iControl REST","severity":"critical","exploited":false,"published_at":"2026-05-13T16:16:44.777+00:00","url":"https://junglewise.ai/threats/cve-2026-41225-f5-big-ip-arbitrary-command-execution-in-icontrol-rest"},{"cve":"CVE-2026-42930","cvss":8.7,"epss":0.0051,"slug":"cve-2026-42930-f5-big-ip-appliance-mode-restriction-bypass-via-path-traversal","title":"F5 BIG-IP Appliance mode restriction bypass via path traversal","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:49.777+00:00","url":"https://junglewise.ai/threats/cve-2026-42930-f5-big-ip-appliance-mode-restriction-bypass-via-path-traversal"},{"cve":"CVE-2026-42924","cvss":8.7,"epss":0.0025,"slug":"cve-2026-42924-f5-big-ip-privilege-escalation-in-icontrol-soap-via-snmp","title":"F5 BIG-IP privilege escalation in iControl SOAP via SNMP configuration","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:49.517+00:00","url":"https://junglewise.ai/threats/cve-2026-42924-f5-big-ip-privilege-escalation-in-icontrol-soap-via-snmp"}],"high":17,"name":"F5 BIG-IP Access Policy Manager","rank":20,"slug":"big-ip-access-policy-manager","score":67,"vendor":{"name":"F5","slug":"f5"},"critical":1,"max_cvss":9.1,"max_epss":0.0089,"exploited":0,"vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/big-ip-access-policy-manager"},{"hub":true,"top":[{"cve":"CVE-2026-44006","cvss":10,"epss":0.0077,"slug":"cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access","title":"patriksimek vm2 sandbox escape via arbitrary prototype access","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.387+00:00","url":"https://junglewise.ai/threats/cve-2026-44006-patriksimek-vm2-sandbox-escape-via-arbitrary-prototype-access"},{"cve":"CVE-2026-44005","cvss":10,"epss":0.0083,"slug":"cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation","title":"patriksimek vm2 sandbox escape via host prototype mutation","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:17.257+00:00","url":"https://junglewise.ai/threats/cve-2026-44005-patriksimek-vm2-sandbox-escape-via-host-prototype-mutation"},{"cve":"CVE-2026-43997","cvss":10,"epss":0.0077,"slug":"cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage","title":"patriksimek vm2 sandbox escape via host object leakage","severity":"critical","exploited":false,"published_at":"2026-05-13T18:16:16.177+00:00","url":"https://junglewise.ai/threats/cve-2026-43997-patriksimek-vm2-sandbox-escape-via-host-object-leakage"}],"high":2,"name":"Red Hat Self-service automation portal","rank":21,"slug":"self-service-automation-portal","score":66,"vendor":{"name":"Red Hat","slug":"red-hat"},"critical":10,"max_cvss":10,"max_epss":0.0097,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/self-service-automation-portal"},{"hub":true,"top":[{"cve":"CVE-2026-8135","cvss":8.9,"epss":0.0047,"slug":"cve-2026-8135-concrete-cms-insecure-deserialization-in-expressentrylist-block","title":"Concrete CMS insecure deserialization in ExpressEntryList block","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.97+00:00","url":"https://junglewise.ai/threats/cve-2026-8135-concrete-cms-insecure-deserialization-in-expressentrylist-block"},{"cve":"CVE-2026-8428","cvss":7.5,"epss":0.0013,"slug":"cve-2026-8428-concrete-cms-csrf-in-dashboard-update-controller","title":"Concrete CMS CSRF in dashboard update controller","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:34.387+00:00","url":"https://junglewise.ai/threats/cve-2026-8428-concrete-cms-csrf-in-dashboard-update-controller"},{"cve":"CVE-2026-8426","cvss":7.5,"epss":0.0017,"slug":"cve-2026-8426-concrete-cms-csrf-to-remote-code-execution-in-package-upgrades","title":"Concrete CMS CSRF to Remote Code Execution in package upgrades","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:34.243+00:00","url":"https://junglewise.ai/threats/cve-2026-8426-concrete-cms-csrf-to-remote-code-execution-in-package-upgrades"}],"high":10,"name":"Concrete CMS","rank":22,"slug":"concrete-cms","score":64,"vendor":{"name":"Concrete CMS","slug":"concrete-cms"},"critical":0,"max_cvss":8.9,"max_epss":0.0074,"exploited":0,"vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/concrete-cms"},{"hub":true,"top":[{"cve":"CVE-2026-8135","cvss":8.9,"epss":0.0047,"slug":"cve-2026-8135-concrete-cms-insecure-deserialization-in-expressentrylist-block","title":"Concrete CMS insecure deserialization in ExpressEntryList block","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:32.97+00:00","url":"https://junglewise.ai/threats/cve-2026-8135-concrete-cms-insecure-deserialization-in-expressentrylist-block"},{"cve":"CVE-2026-8428","cvss":7.5,"epss":0.0013,"slug":"cve-2026-8428-concrete-cms-csrf-in-dashboard-update-controller","title":"Concrete CMS CSRF in dashboard update controller","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:34.387+00:00","url":"https://junglewise.ai/threats/cve-2026-8428-concrete-cms-csrf-in-dashboard-update-controller"},{"cve":"CVE-2026-8426","cvss":7.5,"epss":0.0017,"slug":"cve-2026-8426-concrete-cms-csrf-to-remote-code-execution-in-package-upgrades","title":"Concrete CMS CSRF to Remote Code Execution in package upgrades","severity":"high","exploited":false,"published_at":"2026-05-21T21:16:34.243+00:00","url":"https://junglewise.ai/threats/cve-2026-8426-concrete-cms-csrf-to-remote-code-execution-in-package-upgrades"}],"high":10,"name":"Composer Concrete5/Concrete5","rank":23,"slug":"concrete5-concrete5","score":64,"vendor":{"name":"Composer","slug":"composer"},"critical":0,"max_cvss":8.9,"max_epss":0.0074,"exploited":0,"vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"hub":true,"top":[{"cve":"CVE-2026-8401","cvss":9.8,"epss":0.0006,"slug":"cve-2026-8401-mozilla-firefox-sandbox-escape-in-profile-backup","title":"Mozilla Firefox sandbox escape in Profile Backup","severity":"critical","exploited":false,"published_at":"2026-05-12T15:16:20.1+00:00","url":"https://junglewise.ai/threats/cve-2026-8401-mozilla-firefox-sandbox-escape-in-profile-backup"},{"cve":"CVE-2026-8094","cvss":9.8,"epss":0.0044,"slug":"cve-2026-8094-mozilla-firefox-and-thunderbird-code-injection-in-webrtc","title":"Mozilla Firefox and Thunderbird code injection in WebRTC","severity":"critical","exploited":false,"published_at":"2026-05-07T13:16:14.43+00:00","url":"https://junglewise.ai/threats/cve-2026-8094-mozilla-firefox-and-thunderbird-code-injection-in-webrtc"},{"cve":"CVE-2026-8091","cvss":9.8,"epss":0.0048,"slug":"cve-2026-8091-mozilla-firefox-and-thunderbird-incorrect-boundary-conditions-in","title":"Mozilla Firefox and Thunderbird incorrect boundary conditions in Audio/Video Playback","severity":"critical","exploited":false,"published_at":"2026-05-07T13:16:14.087+00:00","url":"https://junglewise.ai/threats/cve-2026-8091-mozilla-firefox-and-thunderbird-incorrect-boundary-conditions-in"}],"high":5,"name":"Mozilla Firefox","rank":24,"slug":"firefox","score":64,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":3,"max_cvss":9.8,"max_epss":0.0048,"exploited":0,"vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/firefox"},{"hub":true,"top":[{"cve":"CVE-2026-44050","cvss":9.9,"slug":"cve-2026-44050-netatalk-heap-buffer-overflow-in-cnid-daemon-comm-rcv","title":"Netatalk heap buffer overflow in CNID daemon comm_rcv","severity":"critical","exploited":false,"published_at":"2026-05-21T08:16:20.58+00:00","url":"https://junglewise.ai/threats/cve-2026-44050-netatalk-heap-buffer-overflow-in-cnid-daemon-comm-rcv"},{"cve":"CVE-2026-44048","cvss":8.8,"slug":"cve-2026-44048-netatalk-stack-buffer-overflow-in-convert-charset","title":"Netatalk stack buffer overflow in convert_charset","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:20.36+00:00","url":"https://junglewise.ai/threats/cve-2026-44048-netatalk-stack-buffer-overflow-in-convert-charset"},{"cve":"CVE-2026-44047","cvss":8.8,"slug":"cve-2026-44047-netatalk-sql-injection-in-mysql-cnid-backend","title":"Netatalk SQL injection in MySQL CNID backend","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:20.173+00:00","url":"https://junglewise.ai/threats/cve-2026-44047-netatalk-sql-injection-in-mysql-cnid-backend"}],"high":13,"name":"Netatalk","rank":25,"slug":"netatalk","score":64,"vendor":{"name":"Netatalk","slug":"netatalk"},"critical":1,"max_cvss":9.9,"max_epss":null,"exploited":0,"vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/netatalk"}],"previous":{"key":"2026-04","top":"Linux Kernel","period":{"end":"2026-04-30","start":"2026-04-01"},"totals":{"high":1331,"critical":379,"exploited":35,"technologies":2159,"vulnerabilities":3561},"url":"https://junglewise.ai/threats/monthly/2026-04"},"next":{"key":"2026-06","top":"Google Chrome","period":{"end":"2026-06-30","start":"2026-06-01"},"totals":{"high":2357,"critical":706,"exploited":29,"technologies":3934,"vulnerabilities":8427},"url":"https://junglewise.ai/threats/monthly/2026-06"}}