Monthly report
Most vulnerable technologies in August 2026
Final report, published . It does not change.
In August 2026, Junglewise Threat Intelligence recorded 8,028 new vulnerabilities: 1,015 critical, 2,982 high and 24 exploited in the wild. The most vulnerable technology was Linux Kernel, with 972 vulnerabilities (147 critical, 1 exploited in the wild), followed by Google Chrome (334) and IBM AIX (73).
- New vulnerabilities
- 8,028
- Critical
- 1,015
- Exploited in the wild
- 24
- Technologies affected
- 3,961
Ranking
Most affected vendors
- 1.Linux972 vulnerabilities, 147 critical, 1 exploited
- 2.Oracle295 vulnerabilities, 31 critical, 0 exploited
- 3.Google352 vulnerabilities, 46 critical, 0 exploited
- 4.Microsoft246 vulnerabilities, 24 critical, 3 exploited
- 5.IBM175 vulnerabilities, 24 critical, 0 exploited
- 6.Npm191 vulnerabilities, 35 critical, 0 exploited
- 7.Pip190 vulnerabilities, 15 critical, 1 exploited
- 8.Go143 vulnerabilities, 22 critical, 1 exploited
- 9.Apache83 vulnerabilities, 20 critical, 0 exploited
- 10.Composer101 vulnerabilities, 5 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-72898: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and…criticalexploited in the wildCVSS 10EPSS 19.1%
- CVE-2026-5430: The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported…criticalexploited in the wildCVSS 10EPSS 0.6%
- CVE-2021-23758: Ajax.NET Professional unsafe deserialization of untrusted datacriticalexploited in the wildCVSS 9.8EPSS 82.6%
- CVE-2026-60004: Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.criticalexploited in the wildCVSS 9.8EPSS 24.0%
- CVE-2026-82329: JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated…criticalexploited in the wildCVSS 9.8EPSS 14.1%
- CVE-2026-73570: Zimbra Collaboration Suite OS command injection in SMTPcriticalexploited in the wildCVSS 9.8EPSS 11.7%
- CVE-2026-81578: An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under…criticalexploited in the wildCVSS 9.8EPSS 4.5%
- CVE-2026-72529: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X…criticalexploited in the wildCVSS 9.8EPSS 1.5%
- CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS…criticalexploited in the wildCVSS 9.8EPSS 1.2%
- CVE-2026-64849: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to…criticalexploited in the wildCVSS 9.3EPSS 9.8%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/monthly/2026-08.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in August 2026", https://junglewise.ai/threats/monthly/2026-08, 26 September 2026.