{"schema_version":1,"title":"Most vulnerable technologies in June 2026","summary":"In June 2026, Junglewise Threat Intelligence recorded 8,427 new vulnerabilities: 706 critical, 2,357 high and 29 exploited in the wild. The most vulnerable technology was Google Chrome, with 947 vulnerabilities (2 critical, 1 exploited in the wild), followed by Linux Kernel (397) and Openclaw (128).","url":"https://junglewise.ai/threats/monthly/2026-06","json_url":"https://junglewise.ai/threats/monthly/2026-06.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/monthly/2026-06","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"month","period":{"end":"2026-06-30","start":"2026-06-01"},"totals":{"high":2357,"critical":706,"exploited":29,"technologies":3934,"vulnerabilities":8427},"notable":[{"cve":"CVE-2026-10520","cvss":10,"epss":0.0328,"slug":"cve-2026-10520-ivanti-sentry-os-command-injection-allows-remote-code-execution","title":"Ivanti Sentry OS command injection allows remote code execution","severity":"critical","exploited":true,"published_at":"2026-06-09T16:16:35.7+00:00","url":"https://junglewise.ai/threats/cve-2026-10520-ivanti-sentry-os-command-injection-allows-remote-code-execution"},{"cve":"CVE-2026-49869","cvss":10,"epss":0.021,"slug":"cve-2026-49869-kestra-oss-authentication-bypass-in-authenticationfilter","title":"Kestra OSS authentication bypass in AuthenticationFilter","severity":"critical","exploited":true,"published_at":"2026-06-26T22:16:32.113+00:00","url":"https://junglewise.ai/threats/cve-2026-49869-kestra-oss-authentication-bypass-in-authenticationfilter"},{"cve":"CVE-2026-48282","cvss":10,"epss":0.0102,"slug":"cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions","title":"Adobe ColdFusion path traversal in multiple versions","severity":"critical","exploited":true,"published_at":"2026-06-30T16:16:54.533+00:00","url":"https://junglewise.ai/threats/cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions"},{"cve":"CVE-2026-48907","cvss":10,"epss":0.0084,"slug":"cve-2026-48907-joomla-jce-editor-improper-access-control-leading-to-rce","title":"Joomla JCE Editor improper access control leading to RCE","severity":"critical","exploited":true,"published_at":"2026-06-05T08:16:30.797+00:00","url":"https://junglewise.ai/threats/cve-2026-48907-joomla-jce-editor-improper-access-control-leading-to-rce"},{"cve":"CVE-2026-48908","cvss":10,"epss":0.008,"slug":"cve-2026-48908-joomshaper-sp-page-builder-arbitrary-file-upload-in-joomla","title":"JoomShaper SP Page Builder arbitrary file upload in Joomla","severity":"critical","exploited":true,"published_at":"2026-06-20T13:16:42.08+00:00","url":"https://junglewise.ai/threats/cve-2026-48908-joomshaper-sp-page-builder-arbitrary-file-upload-in-joomla"},{"cve":"CVE-2026-48558","cvss":10,"epss":0.0072,"slug":"cve-2026-48558-simplehelp-authentication-bypass-in-oidc-authentication-flow","title":"SimpleHelp authentication bypass in OIDC authentication flow","severity":"critical","exploited":true,"published_at":"2026-06-12T18:16:35.317+00:00","url":"https://junglewise.ai/threats/cve-2026-48558-simplehelp-authentication-bypass-in-oidc-authentication-flow"},{"cve":"CVE-2026-48939","cvss":10,"epss":0.0056,"slug":"cve-2026-48939-joomla-icagenda-arbitrary-file-upload-in-file-attachment-feature","title":"Joomla iCagenda arbitrary file upload in file attachment feature","severity":"critical","exploited":true,"published_at":"2026-06-20T13:16:42.433+00:00","url":"https://junglewise.ai/threats/cve-2026-48939-joomla-icagenda-arbitrary-file-upload-in-file-attachment-feature"},{"cve":"CVE-2026-56290","cvss":10,"epss":0.0036,"slug":"cve-2026-56290-joomlack-page-builder-ck-unauthenticated-arbitrary-file-upload","title":"Joomlack Page Builder CK unauthenticated arbitrary file upload","severity":"critical","exploited":true,"published_at":"2026-06-29T15:16:42.36+00:00","url":"https://junglewise.ai/threats/cve-2026-56290-joomlack-page-builder-ck-unauthenticated-arbitrary-file-upload"},{"cve":"CVE-2026-55255","cvss":9.9,"epss":0.0023,"slug":"cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow","title":"Langflow IDOR in responses endpoint allows cross-user flow execution","severity":"critical","exploited":true,"published_at":"2026-06-23T17:17:08.05+00:00","url":"https://junglewise.ai/threats/cve-2026-55255-langflow-idor-in-responses-endpoint-allows-cross-user-flow"},{"cve":"CVE-2026-25089","cvss":9.8,"epss":0.2339,"slug":"cve-2026-25089-fortinet-fortisandbox-os-command-injection-in-web-ui","title":"Fortinet FortiSandbox OS command injection in Web UI","severity":"critical","exploited":true,"published_at":"2026-06-09T16:16:39.943+00:00","url":"https://junglewise.ai/threats/cve-2026-25089-fortinet-fortisandbox-os-command-injection-in-web-ui"}],"vendors":[{"hub":true,"high":34,"name":"Google","rank":1,"slug":"google","critical":8,"exploited":2,"vulnerabilities":1091,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":91,"name":"Oracle","rank":2,"slug":"oracle","critical":121,"exploited":2,"vulnerabilities":230,"url":"https://junglewise.ai/threats/vendors/oracle"},{"hub":true,"high":96,"name":"Npm","rank":3,"slug":"npm","critical":34,"exploited":0,"vulnerabilities":263,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":96,"name":"Pip","rank":4,"slug":"pip","critical":37,"exploited":0,"vulnerabilities":235,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":141,"name":"Microsoft","rank":5,"slug":"microsoft","critical":16,"exploited":2,"vulnerabilities":220,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":91,"name":"Go","rank":6,"slug":"go","critical":32,"exploited":0,"vulnerabilities":204,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":1,"name":"Linux","rank":7,"slug":"linux","critical":2,"exploited":2,"vulnerabilities":398,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":51,"name":"Adobe","rank":8,"slug":"adobe","critical":12,"exploited":1,"vulnerabilities":86,"url":"https://junglewise.ai/threats/vendors/adobe"},{"hub":true,"high":51,"name":"Openclaw","rank":9,"slug":"openclaw","critical":2,"exploited":0,"vulnerabilities":129,"url":"https://junglewise.ai/threats/vendors/openclaw"},{"hub":true,"high":55,"name":"ThemeREX","rank":10,"slug":"themerex","critical":6,"exploited":0,"vulnerabilities":61,"url":"https://junglewise.ai/threats/vendors/themerex"}],"generated_at":"2026-09-26T09:24:00.138874+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-11645","cvss":8.8,"epss":0.0008,"slug":"cve-2026-11645-google-chrome-v8-out-of-bounds-read-and-write","title":"Google Chrome V8 out of bounds read and write","severity":"critical","exploited":true,"published_at":"2026-06-09T00:16:47.37+00:00","url":"https://junglewise.ai/threats/cve-2026-11645-google-chrome-v8-out-of-bounds-read-and-write"},{"cve":"CVE-2026-12440","cvss":9.6,"epss":0.0031,"slug":"cve-2026-12440-google-chrome-use-after-free-in-digitalcredentials","title":"Google Chrome use after free in DigitalCredentials","severity":"critical","exploited":false,"published_at":"2026-06-17T13:19:59.187+00:00","url":"https://junglewise.ai/threats/cve-2026-12440-google-chrome-use-after-free-in-digitalcredentials"},{"cve":"CVE-2026-12466","cvss":8.8,"epss":0.004,"slug":"cve-2026-12466-google-chrome-heap-buffer-overflow-in-webrtc","title":"Google Chrome heap buffer overflow in WebRTC","severity":"high","exploited":false,"published_at":"2026-06-17T13:20:03.843+00:00","url":"https://junglewise.ai/threats/cve-2026-12466-google-chrome-heap-buffer-overflow-in-webrtc"}],"high":18,"name":"Google Chrome","rank":1,"slug":"chrome","score":1003,"vendor":{"name":"Google","slug":"google"},"critical":2,"max_cvss":10,"max_epss":0.0044,"exploited":1,"vulnerabilities":947,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2022-0492","cvss":7.8,"epss":0.0524,"slug":"cve-2022-0492-linux-kernel-privilege-escalation-in-cgroups-v1-release-agent","title":"Linux Kernel privilege escalation in cgroups v1 release_agent","severity":"critical","exploited":true,"published_at":"2026-06-02T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0492-linux-kernel-privilege-escalation-in-cgroups-v1-release-agent"},{"cve":"CVE-2026-53266","epss":0.0065,"slug":"cve-2026-53266-linux-kernel-netfilter-improper-memory-write-in-ebt-snat-arp","title":"Linux Kernel netfilter improper memory write in ebt_snat ARP rewrite","severity":"critical","exploited":true,"published_at":"2026-06-25T09:16:44.643+00:00","url":"https://junglewise.ai/threats/cve-2026-53266-linux-kernel-netfilter-improper-memory-write-in-ebt-snat-arp"},{"cve":"CVE-2026-45476","cvss":8.2,"slug":"cve-2026-45476-linux-mana-driver-use-after-free-privilege-escalation","title":"Linux MANA Driver use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-06-09T17:17:22.14+00:00","url":"https://junglewise.ai/threats/cve-2026-45476-linux-mana-driver-use-after-free-privilege-escalation"}],"high":1,"name":"Linux Kernel","rank":2,"slug":"kernel","score":429,"vendor":{"name":"Linux","slug":"linux"},"critical":2,"max_cvss":8.2,"max_epss":0.0524,"exploited":2,"vulnerabilities":397,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cvss":9.8,"slug":"openclaw-node-pairing-state-mutation-on-reconnection-40b03ce4","title":"OpenClaw node pairing state mutation on reconnection","severity":"critical","exploited":false,"published_at":"2026-06-13T00:34:33+00:00","url":"https://junglewise.ai/threats/openclaw-node-pairing-state-mutation-on-reconnection-40b03ce4"},{"cve":"CVE-2026-53838","cvss":9.8,"epss":0.0037,"slug":"cve-2026-53838-openclaw-state-mutation-in-node-pairing-reconnection","title":"OpenClaw state mutation in node pairing reconnection","severity":"critical","exploited":false,"published_at":"2026-06-12T22:16:55.723+00:00","url":"https://junglewise.ai/threats/cve-2026-53838-openclaw-state-mutation-in-node-pairing-reconnection"},{"cvss":8.8,"slug":"openclaw-authorization-bypass-via-pairing-scoped-device-session-6eb9e5ad","title":"OpenClaw authorization bypass via pairing-scoped device session","severity":"high","exploited":false,"published_at":"2026-06-16T21:31:57+00:00","url":"https://junglewise.ai/threats/openclaw-authorization-bypass-via-pairing-scoped-device-session-6eb9e5ad"}],"high":50,"name":"Openclaw","rank":3,"slug":"openclaw","score":238,"vendor":{"name":"Openclaw","slug":"openclaw"},"critical":2,"max_cvss":9.8,"max_epss":0.0196,"exploited":0,"vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/openclaw"},{"hub":true,"top":[{"cvss":10,"slug":"picklescan-blocklist-bypass-via-pkgutil-resolve-name-74c87206","title":"PickleScan blocklist bypass via pkgutil.resolve_name","severity":"critical","exploited":false,"published_at":"2026-06-17T18:35:57+00:00","url":"https://junglewise.ai/threats/picklescan-blocklist-bypass-via-pkgutil-resolve-name-74c87206"},{"cve":"CVE-2026-3490","cvss":10,"epss":0.0062,"slug":"cve-2026-3490-picklescan-blocklist-bypass-via-pkgutil-resolve-name","title":"picklescan blocklist bypass via pkgutil.resolve_name","severity":"critical","exploited":false,"published_at":"2026-06-17T17:16:50.727+00:00","url":"https://junglewise.ai/threats/cve-2026-3490-picklescan-blocklist-bypass-via-pkgutil-resolve-name"},{"cvss":9.8,"slug":"picklescan-incomplete-blocklist-rce-via-stdlib-modules-3e253cc3","title":"PickleScan incomplete blocklist RCE via stdlib modules","severity":"critical","exploited":false,"published_at":"2026-06-23T15:32:36+00:00","url":"https://junglewise.ai/threats/picklescan-incomplete-blocklist-rce-via-stdlib-modules-3e253cc3"}],"high":34,"name":"Pip Picklescan","rank":4,"slug":"picklescan","score":201,"vendor":{"name":"Pip","slug":"pip"},"critical":16,"max_cvss":10,"max_epss":0.0115,"exploited":0,"vulnerabilities":53,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"hub":true,"top":[{"cve":"CVE-2026-47291","cvss":9.8,"slug":"cve-2026-47291-microsoft-windows-integer-overflow-in-http-sys","title":"Microsoft Windows integer overflow in HTTP.sys","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:34.627+00:00","url":"https://junglewise.ai/threats/cve-2026-47291-microsoft-windows-integer-overflow-in-http-sys"},{"cve":"CVE-2026-45657","cvss":9.8,"slug":"cve-2026-45657-microsoft-windows-kernel-use-after-free-remote-code-execution","title":"Microsoft Windows Kernel use after free remote code execution","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:33+00:00","url":"https://junglewise.ai/threats/cve-2026-45657-microsoft-windows-kernel-use-after-free-remote-code-execution"},{"cve":"CVE-2026-44815","cvss":9.8,"slug":"cve-2026-44815-microsoft-windows-stack-overflow-in-dhcp-client","title":"Microsoft Windows stack overflow in DHCP Client","severity":"critical","exploited":false,"published_at":"2026-06-09T17:17:17.717+00:00","url":"https://junglewise.ai/threats/cve-2026-44815-microsoft-windows-stack-overflow-in-dhcp-client"}],"high":42,"name":"Microsoft Windows","rank":5,"slug":"windows-","score":160,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":4,"max_cvss":9.8,"max_epss":null,"exploited":0,"vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2026-35323","cvss":9.9,"epss":0.0048,"slug":"cve-2026-35323-oracle-webcenter-content-improper-access-control-in-content","title":"Oracle WebCenter Content improper access control in Content Server","severity":"critical","exploited":false,"published_at":"2026-06-17T10:40:24.513+00:00","url":"https://junglewise.ai/threats/cve-2026-35323-oracle-webcenter-content-improper-access-control-in-content"},{"cve":"CVE-2026-35321","cvss":9.9,"epss":0.0048,"slug":"cve-2026-35321-oracle-webcenter-content-improper-access-control-in-content","title":"Oracle WebCenter Content improper access control in Content Server","severity":"critical","exploited":false,"published_at":"2026-06-17T10:40:24.303+00:00","url":"https://junglewise.ai/threats/cve-2026-35321-oracle-webcenter-content-improper-access-control-in-content"},{"cve":"CVE-2026-35316","cvss":9.9,"epss":0.0048,"slug":"cve-2026-35316-oracle-webcenter-content-improper-access-control-in-content","title":"Oracle WebCenter Content improper access control in Content Server","severity":"critical","exploited":false,"published_at":"2026-06-17T10:40:23.78+00:00","url":"https://junglewise.ai/threats/cve-2026-35316-oracle-webcenter-content-improper-access-control-in-content"}],"high":13,"name":"Oracle WebCenter Content","rank":6,"slug":"webcenter-content","score":130,"vendor":{"name":"Oracle","slug":"oracle"},"critical":15,"max_cvss":9.9,"max_epss":0.0052,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/webcenter-content"},{"hub":true,"top":[{"cve":"CVE-2026-56237","cvss":9.1,"slug":"cve-2026-56237-capgo-broken-authentication-in-api-key-generation","title":"Capgo broken authentication in API key generation","severity":"critical","exploited":false,"published_at":"2026-06-24T13:16:33.467+00:00","url":"https://junglewise.ai/threats/cve-2026-56237-capgo-broken-authentication-in-api-key-generation"},{"cve":"CVE-2026-56247","cvss":8.8,"slug":"cve-2026-56247-capgo-privilege-escalation-via-cross-scope-rbac-role-assignment","title":"Capgo privilege escalation via cross-scope RBAC role assignment","severity":"high","exploited":false,"published_at":"2026-06-30T23:17:29.107+00:00","url":"https://junglewise.ai/threats/cve-2026-56247-capgo-privilege-escalation-via-cross-scope-rbac-role-assignment"},{"cve":"CVE-2026-56230","cvss":8.8,"slug":"cve-2026-56230-capgo-bola-in-middlewarekey-via-x-limited-key-id-header","title":"Capgo BOLA in middlewareKey via x-limited-key-id header","severity":"high","exploited":false,"published_at":"2026-06-30T23:17:28.853+00:00","url":"https://junglewise.ai/threats/cve-2026-56230-capgo-bola-in-middlewarekey-via-x-limited-key-id-header"}],"high":29,"name":"Capgo","rank":7,"slug":"capgo","score":122,"vendor":{"name":"Capgo","slug":"capgo"},"critical":1,"max_cvss":9.1,"max_epss":null,"exploited":0,"vulnerabilities":59,"url":"https://junglewise.ai/threats/technologies/capgo"},{"hub":true,"top":[{"cve":"CVE-2025-71338","cvss":10,"epss":0.0116,"slug":"cve-2025-71338-flowise-path-traversal-and-arbitrary-file-write-in-document-store","title":"Flowise path traversal and arbitrary file write in document-store API","severity":"critical","exploited":false,"published_at":"2026-06-25T22:16:59.52+00:00","url":"https://junglewise.ai/threats/cve-2025-71338-flowise-path-traversal-and-arbitrary-file-write-in-document-store"},{"cve":"CVE-2026-56274","cvss":9.9,"epss":0.0752,"slug":"cve-2026-56274-flowise-os-command-injection-in-custom-mcp-server-feature","title":"Flowise OS command injection in Custom MCP Server feature","severity":"critical","exploited":false,"published_at":"2026-06-23T13:16:45.083+00:00","url":"https://junglewise.ai/threats/cve-2026-56274-flowise-os-command-injection-in-custom-mcp-server-feature"},{"cve":"CVE-2025-71336","cvss":9.8,"epss":0.0115,"slug":"cve-2025-71336-flowise-remote-code-execution-in-custom-mcp-feature","title":"Flowise remote code execution in Custom MCP feature","severity":"critical","exploited":false,"published_at":"2026-06-25T22:16:59.39+00:00","url":"https://junglewise.ai/threats/cve-2025-71336-flowise-remote-code-execution-in-custom-mcp-feature"}],"high":19,"name":"Npm Flowise","rank":8,"slug":"flowise","score":121,"vendor":{"name":"Npm","slug":"npm"},"critical":9,"max_cvss":10,"max_epss":0.0752,"exploited":0,"vulnerabilities":38,"url":"https://junglewise.ai/threats/technologies/flowise"},{"hub":true,"top":[{"cve":"CVE-2026-54309","cvss":10,"epss":0.0055,"slug":"cve-2026-54309-n8n-missing-authentication-in-mcp-browser-http-transport","title":"n8n missing authentication in MCP Browser HTTP transport","severity":"critical","exploited":false,"published_at":"2026-06-23T16:17:01.86+00:00","url":"https://junglewise.ai/threats/cve-2026-54309-n8n-missing-authentication-in-mcp-browser-http-transport"},{"cve":"CVE-2026-54305","cvss":9.9,"epss":0.0037,"slug":"cve-2026-54305-n8n-improper-access-control-in-dynamic-credentials-ee-endpoints","title":"n8n improper access control in Dynamic Credentials EE endpoints","severity":"critical","exploited":false,"published_at":"2026-06-23T17:17:06.743+00:00","url":"https://junglewise.ai/threats/cve-2026-54305-n8n-improper-access-control-in-dynamic-credentials-ee-endpoints"},{"cve":"CVE-2026-44791","cvss":9.9,"epss":0.0054,"slug":"cve-2026-44791-n8n-prototype-pollution-in-xml-node-leading-to-rce","title":"n8n prototype pollution in XML node leading to RCE","severity":"critical","exploited":false,"published_at":"2026-06-23T17:16:59.547+00:00","url":"https://junglewise.ai/threats/cve-2026-44791-n8n-prototype-pollution-in-xml-node-leading-to-rce"}],"high":13,"name":"N8n","rank":9,"slug":"n8n","score":98,"vendor":{"name":"N8n","slug":"n8n"},"critical":8,"max_cvss":10,"max_epss":0.0055,"exploited":0,"vulnerabilities":32,"url":"https://junglewise.ai/threats/technologies/n8n"},{"hub":true,"top":[{"cve":"CVE-2026-48282","cvss":10,"epss":0.0102,"slug":"cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions","title":"Adobe ColdFusion path traversal in multiple versions","severity":"critical","exploited":true,"published_at":"2026-06-30T16:16:54.533+00:00","url":"https://junglewise.ai/threats/cve-2026-48282-adobe-coldfusion-path-traversal-in-multiple-versions"},{"cve":"CVE-2026-48283","cvss":10,"slug":"cve-2026-48283-adobe-coldfusion-unrestricted-file-upload-in-web-server","title":"Adobe ColdFusion unrestricted file upload in web server","severity":"critical","exploited":false,"published_at":"2026-06-30T16:16:54.643+00:00","url":"https://junglewise.ai/threats/cve-2026-48283-adobe-coldfusion-unrestricted-file-upload-in-web-server"},{"cve":"CVE-2026-48281","cvss":10,"slug":"cve-2026-48281-adobe-coldfusion-arbitrary-code-execution-via-improper-input","title":"Adobe ColdFusion arbitrary code execution via improper input validation","severity":"critical","exploited":false,"published_at":"2026-06-30T16:16:54.427+00:00","url":"https://junglewise.ai/threats/cve-2026-48281-adobe-coldfusion-arbitrary-code-execution-via-improper-input"}],"high":7,"name":"Adobe ColdFusion","rank":10,"slug":"coldfusion","score":81,"vendor":{"name":"Adobe","slug":"adobe"},"critical":8,"max_cvss":10,"max_epss":0.0102,"exploited":1,"vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/coldfusion"},{"hub":true,"top":[{"cve":"CVE-2026-46909","cvss":9.8,"epss":0.0049,"slug":"cve-2026-46909-oracle-jd-edwards-enterpriseone-tools-authentication-bypass-in","title":"Oracle JD Edwards EnterpriseOne Tools authentication bypass in Infrastructure Security","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:08.71+00:00","url":"https://junglewise.ai/threats/cve-2026-46909-oracle-jd-edwards-enterpriseone-tools-authentication-bypass-in"},{"cve":"CVE-2026-46905","cvss":9.8,"epss":0.0045,"slug":"cve-2026-46905-oracle-jd-edwards-enterpriseone-tools-authentication-bypass-in","title":"Oracle JD Edwards EnterpriseOne Tools authentication bypass in Web Runtime Security","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:08.277+00:00","url":"https://junglewise.ai/threats/cve-2026-46905-oracle-jd-edwards-enterpriseone-tools-authentication-bypass-in"},{"cve":"CVE-2026-46904","cvss":9.8,"epss":0.0045,"slug":"cve-2026-46904-oracle-jd-edwards-enterpriseone-tools-auth-bypass-in","title":"Oracle JD Edwards EnterpriseOne Tools auth bypass in Infrastructure Security","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:08.167+00:00","url":"https://junglewise.ai/threats/cve-2026-46904-oracle-jd-edwards-enterpriseone-tools-auth-bypass-in"}],"high":1,"name":"Oracle JD Edwards EnterpriseOne Tools","rank":11,"slug":"jd-edwards-enterpriseone-tools","score":81,"vendor":{"name":"Oracle","slug":"oracle"},"critical":13,"max_cvss":9.8,"max_epss":0.0049,"exploited":0,"vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/jd-edwards-enterpriseone-tools"},{"hub":true,"top":[{"cve":"CVE-2026-10134","cvss":10,"slug":"cve-2026-10134-ibm-langflow-oss-unauthenticated-rce-in-pythoncodestructuredtool","title":"IBM Langflow OSS unauthenticated RCE in PythonCodeStructuredTool","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:26.883+00:00","url":"https://junglewise.ai/threats/cve-2026-10134-ibm-langflow-oss-unauthenticated-rce-in-pythoncodestructuredtool"},{"cve":"CVE-2026-10561","cvss":10,"slug":"cve-2026-10561-ibm-langflow-oss-remote-code-execution-in-pythonreplcomponent","title":"IBM Langflow OSS remote code execution in PythonREPLComponent","severity":"critical","exploited":false,"published_at":"2026-06-22T14:16:25.023+00:00","url":"https://junglewise.ai/threats/cve-2026-10561-ibm-langflow-oss-remote-code-execution-in-pythonreplcomponent"},{"cve":"CVE-2026-7873","cvss":9.9,"slug":"cve-2026-7873-ibm-langflow-oss-code-injection-in-code-validation-endpoint","title":"IBM Langflow OSS code injection in code validation endpoint","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:31.75+00:00","url":"https://junglewise.ai/threats/cve-2026-7873-ibm-langflow-oss-code-injection-in-code-validation-endpoint"}],"high":5,"name":"IBM Langflow","rank":12,"slug":"langflow-oss","score":69,"vendor":{"name":"IBM","slug":"ibm"},"critical":9,"max_cvss":10,"max_epss":null,"exploited":0,"vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"hub":true,"top":[{"cve":"CVE-2026-46855","cvss":9.9,"epss":0.0048,"slug":"cve-2026-46855-oracle-enterprise-manager-base-platform-improper-access-control","title":"Oracle Enterprise Manager Base Platform improper access control in Metadata Plugin","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:03.117+00:00","url":"https://junglewise.ai/threats/cve-2026-46855-oracle-enterprise-manager-base-platform-improper-access-control"},{"cve":"CVE-2026-46854","cvss":9.9,"epss":0.0045,"slug":"cve-2026-46854-oracle-enterprise-manager-base-platform-access-control-bypass-in","title":"Oracle Enterprise Manager Base Platform access control bypass in Target Management","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:03.013+00:00","url":"https://junglewise.ai/threats/cve-2026-46854-oracle-enterprise-manager-base-platform-access-control-bypass-in"},{"cve":"CVE-2026-46852","cvss":9.9,"epss":0.0048,"slug":"cve-2026-46852-oracle-enterprise-manager-privilege-escalation-in-metadata-plugin","title":"Oracle Enterprise Manager privilege escalation in Metadata Plugin","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:02.803+00:00","url":"https://junglewise.ai/threats/cve-2026-46852-oracle-enterprise-manager-privilege-escalation-in-metadata-plugin"}],"high":5,"name":"Oracle Enterprise Manager Base Platform","rank":13,"slug":"enterprise-manager-base-platform","score":69,"vendor":{"name":"Oracle","slug":"oracle"},"critical":9,"max_cvss":9.9,"max_epss":0.0052,"exploited":0,"vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/enterprise-manager-base-platform"},{"hub":true,"top":[{"cve":"CVE-2025-48640","cvss":8,"epss":0.0013,"slug":"cve-2025-48640-google-android-privilege-escalation-in-system-passkey-pairing","title":"Google Android privilege escalation in System passkey pairing","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:14.04+00:00","url":"https://junglewise.ai/threats/cve-2025-48640-google-android-privilege-escalation-in-system-passkey-pairing"},{"cve":"CVE-2026-0092","cvss":7.8,"epss":0.0024,"slug":"cve-2026-0092-google-android-package-manager-privilege-escalation-in-framework","title":"Google Android Package Manager privilege escalation in Framework","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:26.813+00:00","url":"https://junglewise.ai/threats/cve-2026-0092-google-android-package-manager-privilege-escalation-in-framework"},{"cve":"CVE-2026-0019","cvss":7.8,"epss":0.0013,"slug":"cve-2026-0019-google-android-settingslib-privilege-escalation-via-system","title":"Google Android SettingsLib privilege escalation via system component disabling","severity":"high","exploited":false,"published_at":"2026-06-17T13:19:25.533+00:00","url":"https://junglewise.ai/threats/cve-2026-0019-google-android-settingslib-privilege-escalation-via-system"}],"high":4,"name":"Google Android","rank":14,"slug":"android","score":68,"vendor":{"name":"Google","slug":"google"},"critical":0,"max_cvss":10,"max_epss":0.0039,"exploited":0,"vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/android"},{"hub":true,"top":[{"cve":"CVE-2024-21182","cvss":7.5,"epss":0.8767,"slug":"cve-2024-21182-oracle-weblogic-server-unspecified-vulnerability-in-core","title":"Oracle WebLogic Server unspecified vulnerability in Core component","severity":"critical","exploited":true,"published_at":"2026-06-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-21182-oracle-weblogic-server-unspecified-vulnerability-in-core"},{"cve":"CVE-2026-35301","cvss":10,"epss":0.0052,"slug":"cve-2026-35301-oracle-weblogic-server-authentication-bypass-in-console","title":"Oracle WebLogic Server authentication bypass in Console","severity":"critical","exploited":false,"published_at":"2026-06-17T10:40:22.2+00:00","url":"https://junglewise.ai/threats/cve-2026-35301-oracle-weblogic-server-authentication-bypass-in-console"},{"cve":"CVE-2026-35292","cvss":10,"epss":0.0052,"slug":"cve-2026-35292-oracle-weblogic-server-authentication-bypass-in-console","title":"Oracle WebLogic Server authentication bypass in Console","severity":"critical","exploited":false,"published_at":"2026-06-17T10:40:21.323+00:00","url":"https://junglewise.ai/threats/cve-2026-35292-oracle-weblogic-server-authentication-bypass-in-console"}],"high":7,"name":"Oracle WebLogic Server","rank":15,"slug":"weblogic-server","score":68,"vendor":{"name":"Oracle","slug":"oracle"},"critical":6,"max_cvss":10,"max_epss":0.8767,"exploited":1,"vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/weblogic-server"},{"hub":true,"top":[{"cve":"CVE-2026-52813","cvss":10,"slug":"cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names","title":"Gogs path traversal and RCE via organization names","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.353+00:00","url":"https://junglewise.ai/threats/cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names"},{"cve":"CVE-2026-52811","cvss":9.9,"slug":"cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in","title":"Gogs arbitrary file write via symlink following in UploadRepoFiles","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.093+00:00","url":"https://junglewise.ai/threats/cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in"},{"cve":"CVE-2026-52806","cvss":9.9,"slug":"cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection","title":"Gogs Remote Code Execution via git rebase argument injection","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:56.44+00:00","url":"https://junglewise.ai/threats/cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection"}],"high":13,"name":"Gogs","rank":16,"slug":"gogs","score":66,"vendor":{"name":"Gogs","slug":"gogs"},"critical":3,"max_cvss":10,"max_epss":null,"exploited":0,"vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs"},{"hub":true,"top":[{"cve":"CVE-2026-52813","cvss":10,"slug":"cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names","title":"Gogs path traversal and RCE via organization names","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.353+00:00","url":"https://junglewise.ai/threats/cve-2026-52813-gogs-path-traversal-and-rce-via-organization-names"},{"cve":"CVE-2026-52811","cvss":9.9,"slug":"cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in","title":"Gogs arbitrary file write via symlink following in UploadRepoFiles","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:57.093+00:00","url":"https://junglewise.ai/threats/cve-2026-52811-gogs-arbitrary-file-write-via-symlink-following-in"},{"cve":"CVE-2026-52806","cvss":9.9,"slug":"cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection","title":"Gogs Remote Code Execution via git rebase argument injection","severity":"critical","exploited":false,"published_at":"2026-06-24T21:16:56.44+00:00","url":"https://junglewise.ai/threats/cve-2026-52806-gogs-remote-code-execution-via-git-rebase-argument-injection"}],"high":13,"name":"Gogs.io/Gogs","rank":17,"slug":"gogs-io-gogs","score":65,"vendor":{"name":"Go","slug":"go"},"critical":3,"max_cvss":10,"max_epss":null,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"hub":true,"top":[{"cve":"CVE-2026-50566","cvss":9.9,"epss":0.0029,"slug":"cve-2026-50566-fission-privilege-escalation-via-environment-container","title":"Fission privilege escalation via Environment Container SecurityContext bypass","severity":"critical","exploited":false,"published_at":"2026-06-10T18:17:13.04+00:00","url":"https://junglewise.ai/threats/cve-2026-50566-fission-privilege-escalation-via-environment-container"},{"cve":"CVE-2026-50564","cvss":9.9,"epss":0.0027,"slug":"cve-2026-50564-fission-privilege-escalation-via-podspec-injection-in-environment","title":"Fission privilege escalation via PodSpec injection in Environment CRD","severity":"critical","exploited":false,"published_at":"2026-06-10T18:17:12.74+00:00","url":"https://junglewise.ai/threats/cve-2026-50564-fission-privilege-escalation-via-podspec-injection-in-environment"},{"cve":"CVE-2026-50563","cvss":9.9,"epss":0.0027,"slug":"cve-2026-50563-fission-container-executor-privilege-escalation-via-podspec","title":"Fission Container Executor privilege escalation via PodSpec injection","severity":"critical","exploited":false,"published_at":"2026-06-10T18:17:12.607+00:00","url":"https://junglewise.ai/threats/cve-2026-50563-fission-container-executor-privilege-escalation-via-podspec"}],"high":9,"name":"Fission","rank":18,"slug":"fission","score":61,"vendor":{"name":"Fission","slug":"fission"},"critical":5,"max_cvss":9.9,"max_epss":0.003,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/fission"},{"hub":true,"top":[{"cve":"CVE-2026-50566","cvss":9.9,"epss":0.0029,"slug":"cve-2026-50566-fission-privilege-escalation-via-environment-container","title":"Fission privilege escalation via Environment Container SecurityContext bypass","severity":"critical","exploited":false,"published_at":"2026-06-10T18:17:13.04+00:00","url":"https://junglewise.ai/threats/cve-2026-50566-fission-privilege-escalation-via-environment-container"},{"cve":"CVE-2026-50564","cvss":9.9,"epss":0.0027,"slug":"cve-2026-50564-fission-privilege-escalation-via-podspec-injection-in-environment","title":"Fission privilege escalation via PodSpec injection in Environment CRD","severity":"critical","exploited":false,"published_at":"2026-06-10T18:17:12.74+00:00","url":"https://junglewise.ai/threats/cve-2026-50564-fission-privilege-escalation-via-podspec-injection-in-environment"},{"cve":"CVE-2026-50563","cvss":9.9,"epss":0.0027,"slug":"cve-2026-50563-fission-container-executor-privilege-escalation-via-podspec","title":"Fission Container Executor privilege escalation via PodSpec injection","severity":"critical","exploited":false,"published_at":"2026-06-10T18:17:12.607+00:00","url":"https://junglewise.ai/threats/cve-2026-50563-fission-container-executor-privilege-escalation-via-podspec"}],"high":9,"name":"Go Github.com/Fission/Fission","rank":19,"slug":"github-com-fission-fission","score":61,"vendor":{"name":"Go","slug":"go"},"critical":5,"max_cvss":9.9,"max_epss":0.003,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"hub":true,"top":[{"cve":"CVE-2026-46781","cvss":10,"epss":0.0052,"slug":"cve-2026-46781-oracle-webcenter-enterprise-capture-auth-bypass-in-client-bundle","title":"Oracle WebCenter Enterprise Capture auth bypass in Client Bundle","severity":"critical","exploited":false,"published_at":"2026-06-17T10:53:55.673+00:00","url":"https://junglewise.ai/threats/cve-2026-46781-oracle-webcenter-enterprise-capture-auth-bypass-in-client-bundle"},{"cve":"CVE-2026-46778","cvss":10,"epss":0.0052,"slug":"cve-2026-46778-oracle-webcenter-enterprise-capture-auth-bypass-in-client-bundle","title":"Oracle WebCenter Enterprise Capture auth bypass in Client Bundle","severity":"critical","exploited":false,"published_at":"2026-06-17T10:53:55.363+00:00","url":"https://junglewise.ai/threats/cve-2026-46778-oracle-webcenter-enterprise-capture-auth-bypass-in-client-bundle"},{"cve":"CVE-2026-46782","cvss":9.9,"epss":0.0048,"slug":"cve-2026-46782-oracle-webcenter-enterprise-capture-access-control-bypass-in","title":"Oracle WebCenter Enterprise Capture access control bypass in Client Bundle","severity":"critical","exploited":false,"published_at":"2026-06-17T10:53:55.78+00:00","url":"https://junglewise.ai/threats/cve-2026-46782-oracle-webcenter-enterprise-capture-access-control-bypass-in"}],"high":0,"name":"Oracle WebCenter Enterprise Capture","rank":20,"slug":"webcenter-enterprise-capture","score":60,"vendor":{"name":"Oracle","slug":"oracle"},"critical":10,"max_cvss":10,"max_epss":0.0052,"exploited":0,"vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/webcenter-enterprise-capture"},{"hub":true,"top":[{"cve":"CVE-2026-46846","cvss":10,"epss":0.0052,"slug":"cve-2026-46846-oracle-webcenter-portal-authentication-bypass-in-security","title":"Oracle WebCenter Portal authentication bypass in Security Framework","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:02.14+00:00","url":"https://junglewise.ai/threats/cve-2026-46846-oracle-webcenter-portal-authentication-bypass-in-security"},{"cve":"CVE-2026-46803","cvss":10,"epss":0.0052,"slug":"cve-2026-46803-oracle-webcenter-portal-auth-bypass-in-security-framework","title":"Oracle WebCenter Portal auth bypass in Security Framework","severity":"critical","exploited":false,"published_at":"2026-06-17T10:53:57.947+00:00","url":"https://junglewise.ai/threats/cve-2026-46803-oracle-webcenter-portal-auth-bypass-in-security-framework"},{"cve":"CVE-2026-46847","cvss":9.9,"epss":0.0048,"slug":"cve-2026-46847-oracle-webcenter-portal-compromise-in-runtime-tools","title":"Oracle WebCenter Portal compromise in Runtime Tools","severity":"critical","exploited":false,"published_at":"2026-06-17T10:54:02.28+00:00","url":"https://junglewise.ai/threats/cve-2026-46847-oracle-webcenter-portal-compromise-in-runtime-tools"}],"high":0,"name":"Oracle WebCenter Portal","rank":21,"slug":"webcenter-portal","score":60,"vendor":{"name":"Oracle","slug":"oracle"},"critical":10,"max_cvss":10,"max_epss":0.0052,"exploited":0,"vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/webcenter-portal"},{"hub":true,"top":[{"cve":"CVE-2020-9695","cvss":7.8,"slug":"cve-2020-9695-adobe-acrobat-reader-out-of-bounds-write","title":"Adobe Acrobat Reader out-of-bounds write","severity":"high","exploited":false,"published_at":"2026-06-23T18:17:31.403+00:00","url":"https://junglewise.ai/threats/cve-2020-9695-adobe-acrobat-reader-out-of-bounds-write"},{"cve":"CVE-2026-47965","cvss":7.8,"slug":"cve-2026-47965-adobe-acrobat-reader-out-of-bounds-write","title":"Adobe Acrobat Reader out-of-bounds write","severity":"high","exploited":false,"published_at":"2026-06-12T18:16:34.913+00:00","url":"https://junglewise.ai/threats/cve-2026-47965-adobe-acrobat-reader-out-of-bounds-write"},{"cve":"CVE-2026-47959","cvss":7.8,"slug":"cve-2026-47959-adobe-acrobat-reader-stack-based-buffer-overflow","title":"Adobe Acrobat Reader stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-06-09T21:17:24.273+00:00","url":"https://junglewise.ai/threats/cve-2026-47959-adobe-acrobat-reader-stack-based-buffer-overflow"}],"high":17,"name":"Adobe Acrobat Reader","rank":22,"slug":"acrobat-reader","score":58,"vendor":{"name":"Adobe","slug":"adobe"},"critical":0,"max_cvss":7.8,"max_epss":null,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/acrobat-reader"},{"hub":true,"top":[{"cve":"CVE-2026-11712","cvss":9.3,"slug":"cve-2026-11712-ibm-websphere-application-server-xss-in-administrative-console","title":"IBM WebSphere Application Server XSS in administrative console help system","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:27.897+00:00","url":"https://junglewise.ai/threats/cve-2026-11712-ibm-websphere-application-server-xss-in-administrative-console"},{"cve":"CVE-2026-11708","cvss":9.3,"slug":"cve-2026-11708-ibm-websphere-application-server-xss-in-administrative-console","title":"IBM WebSphere Application Server XSS in administrative console help system","severity":"critical","exploited":false,"published_at":"2026-06-30T20:17:27.767+00:00","url":"https://junglewise.ai/threats/cve-2026-11708-ibm-websphere-application-server-xss-in-administrative-console"},{"cve":"CVE-2026-8644","cvss":9.1,"slug":"cve-2026-8644-ibm-websphere-application-server-identity-spoofing-authentication","title":"IBM WebSphere Application Server identity spoofing authentication bypass","severity":"critical","exploited":false,"published_at":"2026-06-01T19:16:55.097+00:00","url":"https://junglewise.ai/threats/cve-2026-8644-ibm-websphere-application-server-identity-spoofing-authentication"}],"high":8,"name":"IBM WebSphere Application Server","rank":23,"slug":"websphere-application-server","score":58,"vendor":{"name":"IBM","slug":"ibm"},"critical":5,"max_cvss":9.3,"max_epss":null,"exploited":0,"vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"hub":true,"top":[{"cve":"CVE-2026-46800","cvss":10,"epss":0.0052,"slug":"cve-2026-46800-oracle-webcenter-sites-authentication-bypass-and-system-takeover","title":"Oracle WebCenter Sites authentication bypass and system takeover","severity":"critical","exploited":false,"published_at":"2026-06-17T10:53:57.63+00:00","url":"https://junglewise.ai/threats/cve-2026-46800-oracle-webcenter-sites-authentication-bypass-and-system-takeover"},{"cve":"CVE-2026-46798","cvss":10,"epss":0.0052,"slug":"cve-2026-46798-oracle-webcenter-sites-authentication-bypass-and-system-takeover","title":"Oracle WebCenter Sites authentication bypass and system takeover","severity":"critical","exploited":false,"published_at":"2026-06-17T10:53:57.42+00:00","url":"https://junglewise.ai/threats/cve-2026-46798-oracle-webcenter-sites-authentication-bypass-and-system-takeover"},{"cve":"CVE-2026-46801","cvss":9.8,"epss":0.0052,"slug":"cve-2026-46801-oracle-webcenter-sites-authentication-bypass","title":"Oracle WebCenter Sites authentication bypass","severity":"critical","exploited":false,"published_at":"2026-06-17T10:53:57.737+00:00","url":"https://junglewise.ai/threats/cve-2026-46801-oracle-webcenter-sites-authentication-bypass"}],"high":3,"name":"Oracle WebCenter Sites","rank":24,"slug":"webcenter-sites","score":57,"vendor":{"name":"Oracle","slug":"oracle"},"critical":8,"max_cvss":10,"max_epss":0.0052,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/webcenter-sites"},{"hub":true,"top":[{"cvss":10,"slug":"crawl4ai-unauthenticated-rce-via-chromium-launch-argument-injection-ffa17c34","title":"Crawl4AI unauthenticated RCE via Chromium launch-argument injection","severity":"critical","exploited":false,"published_at":"2026-06-18T17:25:34+00:00","url":"https://junglewise.ai/threats/crawl4ai-unauthenticated-rce-via-chromium-launch-argument-injection-ffa17c34"},{"cve":"CVE-2026-53753","cvss":9.8,"slug":"cve-2026-53753-unclecode-crawl4ai-sandbox-escape-in-safe-eval-expression","title":"unclecode Crawl4AI sandbox escape in _safe_eval_expression","severity":"critical","exploited":false,"published_at":"2026-06-23T19:17:07.107+00:00","url":"https://junglewise.ai/threats/cve-2026-53753-unclecode-crawl4ai-sandbox-escape-in-safe-eval-expression"},{"cve":"CVE-2026-56265","cvss":9.8,"epss":0.0264,"slug":"cve-2026-56265-crawl4ai-hardcoded-jwt-signing-key-in-docker-api-server","title":"Crawl4AI hardcoded JWT signing key in Docker API server","severity":"critical","exploited":false,"published_at":"2026-06-21T14:16:24.98+00:00","url":"https://junglewise.ai/threats/cve-2026-56265-crawl4ai-hardcoded-jwt-signing-key-in-docker-api-server"}],"high":8,"name":"Pip Crawl4ai","rank":25,"slug":"crawl4ai","score":56,"vendor":{"name":"Pip","slug":"pip"},"critical":5,"max_cvss":10,"max_epss":0.0264,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/crawl4ai"}],"previous":{"key":"2026-05","top":"Linux Kernel","period":{"end":"2026-05-31","start":"2026-05-01"},"totals":{"high":2075,"critical":517,"exploited":26,"technologies":3603,"vulnerabilities":6351},"url":"https://junglewise.ai/threats/monthly/2026-05"},"next":{"key":"2026-07","top":"Microsoft Windows 11","period":{"end":"2026-07-31","start":"2026-07-01"},"totals":{"high":3223,"critical":782,"exploited":23,"technologies":4551,"vulnerabilities":10520},"url":"https://junglewise.ai/threats/monthly/2026-07"}}