Monthly report
Most vulnerable technologies in June 2026
Final report, published . It does not change.
In June 2026, Junglewise Threat Intelligence recorded 8,427 new vulnerabilities: 706 critical, 2,357 high and 29 exploited in the wild. The most vulnerable technology was Google Chrome, with 947 vulnerabilities (2 critical, 1 exploited in the wild), followed by Linux Kernel (397) and Openclaw (128).
- New vulnerabilities
- 8,427
- Critical
- 706
- Exploited in the wild
- 29
- Technologies affected
- 3,934
Ranking
Most affected vendors
- 1.Google1,091 vulnerabilities, 8 critical, 2 exploited
- 2.Oracle230 vulnerabilities, 121 critical, 2 exploited
- 3.Npm263 vulnerabilities, 34 critical, 0 exploited
- 4.Pip235 vulnerabilities, 37 critical, 0 exploited
- 5.Microsoft220 vulnerabilities, 16 critical, 2 exploited
- 6.Go204 vulnerabilities, 32 critical, 0 exploited
- 7.Linux398 vulnerabilities, 2 critical, 2 exploited
- 8.Adobe86 vulnerabilities, 12 critical, 1 exploited
- 9.Openclaw129 vulnerabilities, 2 critical, 0 exploited
- 10.ThemeREX61 vulnerabilities, 6 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-10520: Ivanti Sentry OS command injection allows remote code executioncriticalexploited in the wildCVSS 10EPSS 3.3%
- CVE-2026-49869: Kestra OSS authentication bypass in AuthenticationFiltercriticalexploited in the wildCVSS 10EPSS 2.1%
- CVE-2026-48282: Adobe ColdFusion path traversal in multiple versionscriticalexploited in the wildCVSS 10EPSS 1.0%
- CVE-2026-48907: Joomla JCE Editor improper access control leading to RCEcriticalexploited in the wildCVSS 10EPSS 0.8%
- CVE-2026-48908: JoomShaper SP Page Builder arbitrary file upload in Joomlacriticalexploited in the wildCVSS 10EPSS 0.8%
- CVE-2026-48558: SimpleHelp authentication bypass in OIDC authentication flowcriticalexploited in the wildCVSS 10EPSS 0.7%
- CVE-2026-48939: Joomla iCagenda arbitrary file upload in file attachment featurecriticalexploited in the wildCVSS 10EPSS 0.6%
- CVE-2026-56290: Joomlack Page Builder CK unauthenticated arbitrary file uploadcriticalexploited in the wildCVSS 10EPSS 0.4%
- CVE-2026-55255: Langflow IDOR in responses endpoint allows cross-user flow executioncriticalexploited in the wildCVSS 9.9EPSS 0.2%
- CVE-2026-25089: Fortinet FortiSandbox OS command injection in Web UIcriticalexploited in the wildCVSS 9.8EPSS 23.4%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/monthly/2026-06.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in June 2026", https://junglewise.ai/threats/monthly/2026-06, 26 September 2026.