Junglewise

Monthly report

Most vulnerable technologies in August 2026

Final report, published . It does not change.

In August 2026, Junglewise Threat Intelligence recorded 8,028 new vulnerabilities: 1,015 critical, 2,982 high and 24 exploited in the wild. The most vulnerable technology was Linux Kernel, with 972 vulnerabilities (147 critical, 1 exploited in the wild), followed by Google Chrome (334) and IBM AIX (73).

New vulnerabilities
8,028
Critical
1,015
Exploited in the wild
24
Technologies affected
3,961

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Linux Kernel
Linux
972147454110
2Google Chrome
Google
334448409.8
3IBM AIX
IBM
73124309.9
4IBM PowerVM VIOS
IBM
73124309.9
5Mozilla Thunderbird
Mozilla
521525010
6Mozilla Firefox
Mozilla
521425010
7Microsoft Windows
Microsoft
58738010
8Mozilla Firefox ESR
Mozilla
491225010
9SiYuan
SiYuan
581020010
10Pip Nltk
Pip
5762909.8
11Npm Flowise
Npm
351117010
12Oracle Helidon
Oracle
5561909.8
13Oracle Hyperion Data Relationship Management
Oracle
35726010
14Apple macOS
Apple
498919.8
15Oracle Commerce Experience Manager
Oracle
4072109.3
16Oracle Commerce Guided Search
Oracle
4072109.3
17NLTK Project Natural Language Toolkit
NLTK Project
4552109.8
18Gitpython Project Gitpython
Gitpython Project
4032609.8
19Oracle Hyperion Financial Management
Oracle
49318010
20D-Link DWR-M961
D-Link
1515009.8
21DrayTek VigorSwitch FX2120
DrayTek
2922509.8
22DrayTek VigorSwitch G1280
DrayTek
2922509.8
23DrayTek VigorSwitch G1282
DrayTek
2922509.8
24DrayTek VigorSwitch G2100
DrayTek
2922509.8
25DrayTek VigorSwitch G2121
DrayTek
2922509.8

Most affected vendors

  1. 1.Linux972 vulnerabilities, 147 critical, 1 exploited
  2. 2.Oracle295 vulnerabilities, 31 critical, 0 exploited
  3. 3.Google352 vulnerabilities, 46 critical, 0 exploited
  4. 4.Microsoft246 vulnerabilities, 24 critical, 3 exploited
  5. 5.IBM175 vulnerabilities, 24 critical, 0 exploited
  6. 6.Npm191 vulnerabilities, 35 critical, 0 exploited
  7. 7.Pip190 vulnerabilities, 15 critical, 1 exploited
  8. 8.Go143 vulnerabilities, 22 critical, 1 exploited
  9. 9.Apache83 vulnerabilities, 20 critical, 0 exploited
  10. 10.Composer101 vulnerabilities, 5 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/monthly/2026-08.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies in August 2026", https://junglewise.ai/threats/monthly/2026-08, 26 September 2026.