{"schema_version":1,"title":"Most vulnerable technologies in August 2026","summary":"In August 2026, Junglewise Threat Intelligence recorded 8,028 new vulnerabilities: 1,015 critical, 2,982 high and 24 exploited in the wild. The most vulnerable technology was Linux Kernel, with 972 vulnerabilities (147 critical, 1 exploited in the wild), followed by Google Chrome (334) and IBM AIX (73).","url":"https://junglewise.ai/threats/monthly/2026-08","json_url":"https://junglewise.ai/threats/monthly/2026-08.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/monthly/2026-08","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"month","period":{"end":"2026-08-31","start":"2026-08-01"},"totals":{"high":2982,"critical":1015,"exploited":24,"technologies":3961,"vulnerabilities":8028},"notable":[{"cve":"CVE-2026-72898","cvss":10,"epss":0.1905,"slug":"cve-2026-72898-metabase-sql-injection-in-password-reset-endpoint","title":"Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrato","severity":"critical","exploited":true,"published_at":"2026-08-10T18:18:53.3+00:00","url":"https://junglewise.ai/threats/cve-2026-72898-metabase-sql-injection-in-password-reset-endpoint"},{"cve":"CVE-2026-5430","cvss":10,"epss":0.0058,"slug":"cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability","title":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an a","severity":"critical","exploited":true,"published_at":"2026-08-06T08:16:33.24+00:00","url":"https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability"},{"cve":"CVE-2021-23758","cvss":9.8,"epss":0.8258,"slug":"cve-2021-23758-ajax-net-professional-unsafe-deserialization-of-untrusted-data","title":"Ajax.NET Professional unsafe deserialization of untrusted data","severity":"critical","exploited":true,"published_at":"2026-08-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-23758-ajax-net-professional-unsafe-deserialization-of-untrusted-data"},{"cve":"CVE-2026-60004","cvss":9.8,"epss":0.2399,"slug":"cve-2026-60004-gitea-code-injection-in-diffpatch-api","title":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","severity":"critical","exploited":true,"published_at":"2026-08-26T20:17:56.01+00:00","url":"https://junglewise.ai/threats/cve-2026-60004-gitea-code-injection-in-diffpatch-api"},{"cve":"CVE-2026-82329","cvss":9.8,"epss":0.1412,"slug":"cve-2026-82329-jfrog-artifactory-improper-authentication-vulnerability","title":"JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network","severity":"critical","exploited":true,"published_at":"2026-08-28T20:20:21.293+00:00","url":"https://junglewise.ai/threats/cve-2026-82329-jfrog-artifactory-improper-authentication-vulnerability"},{"cve":"CVE-2026-73570","cvss":9.8,"epss":0.1174,"slug":"cve-2026-73570-zimbra-collaboration-suite-os-command-injection-in-smtp","title":"Zimbra Collaboration Suite OS command injection in SMTP","severity":"critical","exploited":true,"published_at":"2026-08-21T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73570-zimbra-collaboration-suite-os-command-injection-in-smtp"},{"cve":"CVE-2026-81578","cvss":9.8,"epss":0.0448,"slug":"cve-2026-81578-papercut-ng-mf-missing-authentication-for-critical-function","title":"An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, u","severity":"critical","exploited":true,"published_at":"2026-08-28T16:18:29.6+00:00","url":"https://junglewise.ai/threats/cve-2026-81578-papercut-ng-mf-missing-authentication-for-critical-function"},{"cve":"CVE-2026-72529","cvss":9.8,"epss":0.0146,"slug":"cve-2026-72529-trueconf-server-missing-authentication-for-critical-function","title":"A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t","severity":"critical","exploited":true,"published_at":"2026-08-19T17:21:00.99+00:00","url":"https://junglewise.ai/threats/cve-2026-72529-trueconf-server-missing-authentication-for-critical-function"},{"cve":"CVE-2026-65400","cvss":9.8,"epss":0.0122,"slug":"cve-2026-65400-apple-macos-screen-sharing-authentication-bypass","title":"An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, mac","severity":"critical","exploited":true,"published_at":"2026-08-06T22:18:14.533+00:00","url":"https://junglewise.ai/threats/cve-2026-65400-apple-macos-screen-sharing-authentication-bypass"},{"cve":"CVE-2026-64849","cvss":9.3,"epss":0.0984,"slug":"cve-2026-64849-mlflow-server-side-request-forgery","title":"MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauth","severity":"critical","exploited":true,"published_at":"2026-08-17T22:17:23.58+00:00","url":"https://junglewise.ai/threats/cve-2026-64849-mlflow-server-side-request-forgery"}],"vendors":[{"hub":true,"high":454,"name":"Linux","rank":1,"slug":"linux","critical":147,"exploited":1,"vulnerabilities":972,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":167,"name":"Oracle","rank":2,"slug":"oracle","critical":31,"exploited":0,"vulnerabilities":295,"url":"https://junglewise.ai/threats/vendors/oracle"},{"hub":true,"high":92,"name":"Google","rank":3,"slug":"google","critical":46,"exploited":0,"vulnerabilities":352,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":152,"name":"Microsoft","rank":4,"slug":"microsoft","critical":24,"exploited":3,"vulnerabilities":246,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":101,"name":"IBM","rank":5,"slug":"ibm","critical":24,"exploited":0,"vulnerabilities":175,"url":"https://junglewise.ai/threats/vendors/ibm"},{"hub":true,"high":65,"name":"Npm","rank":6,"slug":"npm","critical":35,"exploited":0,"vulnerabilities":191,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":92,"name":"Pip","rank":7,"slug":"pip","critical":15,"exploited":1,"vulnerabilities":190,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":49,"name":"Go","rank":8,"slug":"go","critical":22,"exploited":1,"vulnerabilities":143,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":36,"name":"Apache","rank":9,"slug":"apache","critical":20,"exploited":0,"vulnerabilities":83,"url":"https://junglewise.ai/threats/vendors/apache"},{"hub":true,"high":42,"name":"Composer","rank":10,"slug":"composer","critical":5,"exploited":0,"vulnerabilities":101,"url":"https://junglewise.ai/threats/vendors/composer"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2022-0995","epss":0.0879,"slug":"cve-2022-0995-linux-kernel-out-of-bounds-write-vulnerability","title":"Linux Kernel out-of-bounds write vulnerability","severity":"critical","exploited":true,"published_at":"2026-08-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0995-linux-kernel-out-of-bounds-write-vulnerability"},{"cve":"CVE-2026-76197","cvss":10,"epss":0.0351,"slug":"cve-2026-76197-adobe-campaign-classic-os-command-injection","title":"Adobe Campaign Classic OS command injection","severity":"critical","exploited":false,"published_at":"2026-08-25T18:18:05.11+00:00","url":"https://junglewise.ai/threats/cve-2026-76197-adobe-campaign-classic-os-command-injection"},{"cve":"CVE-2026-76195","cvss":10,"epss":0.0351,"slug":"cve-2026-76195-adobe-campaign-classic-os-command-injection","title":"Adobe Campaign Classic OS command injection","severity":"critical","exploited":false,"published_at":"2026-08-25T18:18:04.967+00:00","url":"https://junglewise.ai/threats/cve-2026-76195-adobe-campaign-classic-os-command-injection"}],"high":454,"name":"Linux Kernel","rank":1,"slug":"kernel","score":2625,"vendor":{"name":"Linux","slug":"linux"},"critical":147,"max_cvss":10,"max_epss":0.0879,"exploited":1,"vulnerabilities":972,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-79152","cvss":9.8,"epss":0.0032,"slug":"cve-2026-79152-google-chrome-customtabs-authorization-bypass-on-android","title":"Google Chrome CustomTabs authorization bypass on Android","severity":"critical","exploited":false,"published_at":"2026-08-25T21:18:10.49+00:00","url":"https://junglewise.ai/threats/cve-2026-79152-google-chrome-customtabs-authorization-bypass-on-android"},{"cve":"CVE-2026-79090","cvss":9.8,"epss":0.0042,"slug":"cve-2026-79090-google-chrome-improper-privilege-management-in-actor","title":"Google Chrome improper privilege management in Actor","severity":"critical","exploited":false,"published_at":"2026-08-25T21:18:04.65+00:00","url":"https://junglewise.ai/threats/cve-2026-79090-google-chrome-improper-privilege-management-in-actor"},{"cve":"CVE-2026-79290","cvss":9.6,"epss":0.0046,"slug":"cve-2026-79290-google-chrome-use-after-free-in-aura","title":"Google Chrome use after free in Aura","severity":"critical","exploited":false,"published_at":"2026-08-25T21:18:23.197+00:00","url":"https://junglewise.ai/threats/cve-2026-79290-google-chrome-use-after-free-in-aura"}],"high":84,"name":"Google Chrome","rank":2,"slug":"chrome","score":722,"vendor":{"name":"Google","slug":"google"},"critical":44,"max_cvss":9.8,"max_epss":0.0057,"exploited":0,"vulnerabilities":334,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-18835","cvss":9.9,"epss":0.0079,"slug":"cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability","title":"IBM AIX and PowerVM VIOS command injection vulnerability","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:17.43+00:00","url":"https://junglewise.ai/threats/cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability"},{"cve":"CVE-2026-17160","cvss":9.8,"epss":0.008,"slug":"cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation","title":"IBM AIX and PowerVM VIOS integer overflow in size computation","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.36+00:00","url":"https://junglewise.ai/threats/cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation"},{"cve":"CVE-2026-17157","cvss":9.8,"epss":0.008,"slug":"cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code","title":"IBM AIX and PowerVM VIOS stack buffer overflow remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.013+00:00","url":"https://junglewise.ai/threats/cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code"}],"high":43,"name":"IBM AIX","rank":3,"slug":"aix","score":219,"vendor":{"name":"IBM","slug":"ibm"},"critical":12,"max_cvss":9.9,"max_epss":0.0103,"exploited":0,"vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/aix"},{"hub":true,"top":[{"cve":"CVE-2026-18835","cvss":9.9,"epss":0.0079,"slug":"cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability","title":"IBM AIX and PowerVM VIOS command injection vulnerability","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:17.43+00:00","url":"https://junglewise.ai/threats/cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability"},{"cve":"CVE-2026-17160","cvss":9.8,"epss":0.008,"slug":"cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation","title":"IBM AIX and PowerVM VIOS integer overflow in size computation","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.36+00:00","url":"https://junglewise.ai/threats/cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation"},{"cve":"CVE-2026-17157","cvss":9.8,"epss":0.008,"slug":"cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code","title":"IBM AIX and PowerVM VIOS stack buffer overflow remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.013+00:00","url":"https://junglewise.ai/threats/cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code"}],"high":43,"name":"IBM PowerVM VIOS","rank":4,"slug":"powervm-vios","score":219,"vendor":{"name":"IBM","slug":"ibm"},"critical":12,"max_cvss":9.9,"max_epss":0.0103,"exploited":0,"vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"hub":true,"top":[{"cve":"CVE-2026-75874","cvss":10,"epss":0.0046,"slug":"cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape","title":"Mozilla Firefox Remote Settings Client sandbox escape","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape"},{"cve":"CVE-2026-74990","cvss":9.8,"epss":0.0072,"slug":"cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs","title":"Mozilla Thunderbird memory corruption in internally found bugs","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.93+00:00","url":"https://junglewise.ai/threats/cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs"},{"cve":"CVE-2026-74989","cvss":9.8,"epss":0.0057,"slug":"cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153","title":"Mozilla Thunderbird memory corruption in version 153","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.81+00:00","url":"https://junglewise.ai/threats/cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153"}],"high":25,"name":"Mozilla Thunderbird","rank":5,"slug":"thunderbird","score":177,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":15,"max_cvss":10,"max_epss":0.0072,"exploited":0,"vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/thunderbird"},{"hub":true,"top":[{"cve":"CVE-2026-75874","cvss":10,"epss":0.0046,"slug":"cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape","title":"Mozilla Firefox Remote Settings Client sandbox escape","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape"},{"cve":"CVE-2026-74990","cvss":9.8,"epss":0.0072,"slug":"cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs","title":"Mozilla Thunderbird memory corruption in internally found bugs","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.93+00:00","url":"https://junglewise.ai/threats/cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs"},{"cve":"CVE-2026-74989","cvss":9.8,"epss":0.0057,"slug":"cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153","title":"Mozilla Thunderbird memory corruption in version 153","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.81+00:00","url":"https://junglewise.ai/threats/cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153"}],"high":25,"name":"Mozilla Firefox","rank":6,"slug":"firefox","score":172,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":14,"max_cvss":10,"max_epss":0.0072,"exploited":0,"vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/firefox"},{"hub":true,"top":[{"cve":"CVE-2026-76197","cvss":10,"epss":0.0351,"slug":"cve-2026-76197-adobe-campaign-classic-os-command-injection","title":"Adobe Campaign Classic OS command injection","severity":"critical","exploited":false,"published_at":"2026-08-25T18:18:05.11+00:00","url":"https://junglewise.ai/threats/cve-2026-76197-adobe-campaign-classic-os-command-injection"},{"cve":"CVE-2026-76195","cvss":10,"epss":0.0351,"slug":"cve-2026-76195-adobe-campaign-classic-os-command-injection","title":"Adobe Campaign Classic OS command injection","severity":"critical","exploited":false,"published_at":"2026-08-25T18:18:04.967+00:00","url":"https://junglewise.ai/threats/cve-2026-76195-adobe-campaign-classic-os-command-injection"},{"cve":"CVE-2026-76193","cvss":10,"epss":0.0128,"slug":"cve-2026-76193-adobe-campaign-classic-server-side-request-forgery-to-code","title":"Adobe Campaign Classic Server-Side Request Forgery to code execution","severity":"critical","exploited":false,"published_at":"2026-08-25T18:18:04.813+00:00","url":"https://junglewise.ai/threats/cve-2026-76193-adobe-campaign-classic-server-side-request-forgery-to-code"}],"high":38,"name":"Microsoft Windows ","rank":7,"slug":"windows-","score":169,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":7,"max_cvss":10,"max_epss":0.0351,"exploited":0,"vulnerabilities":58,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2026-75874","cvss":10,"epss":0.0046,"slug":"cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape","title":"Mozilla Firefox Remote Settings Client sandbox escape","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape"},{"cve":"CVE-2026-74985","cvss":9.8,"epss":0.0053,"slug":"cve-2026-74985-mozilla-firefox-privilege-escalation-in-enterprise-policies","title":"Mozilla Firefox privilege escalation in Enterprise Policies","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.317+00:00","url":"https://junglewise.ai/threats/cve-2026-74985-mozilla-firefox-privilege-escalation-in-enterprise-policies"},{"cve":"CVE-2026-74979","cvss":9.8,"epss":0.0053,"slug":"cve-2026-74979-mozilla-firefox-add-ons-manager-mitigation-bypass","title":"Mozilla Firefox Add-ons Manager mitigation bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:36.683+00:00","url":"https://junglewise.ai/threats/cve-2026-74979-mozilla-firefox-add-ons-manager-mitigation-bypass"}],"high":25,"name":"Mozilla Firefox ESR","rank":8,"slug":"firefox-esr","score":159,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":12,"max_cvss":10,"max_epss":0.0068,"exploited":0,"vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/firefox-esr"},{"hub":true,"top":[{"cvss":10,"slug":"siyuan-sql-injection-in-backlink-mention-search-9ca0d701","title":"SiYuan SQL injection in backlink/mention search","severity":"critical","exploited":false,"published_at":"2026-08-14T12:31:24+00:00","url":"https://junglewise.ai/threats/siyuan-sql-injection-in-backlink-mention-search-9ca0d701"},{"cvss":10,"slug":"siyuan-searchembedblock-sql-injection-1301810a","title":"SiYuan searchEmbedBlock SQL injection","severity":"critical","exploited":false,"published_at":"2026-08-03T15:32:48+00:00","url":"https://junglewise.ai/threats/siyuan-searchembedblock-sql-injection-1301810a"},{"cvss":10,"slug":"siyuan-sql-injection-in-fulltextsearchassetcontent-endpoint-77bd29ce","title":"SiYuan SQL injection in fullTextSearchAssetContent endpoint","severity":"critical","exploited":false,"published_at":"2026-08-03T15:32:48+00:00","url":"https://junglewise.ai/threats/siyuan-sql-injection-in-fulltextsearchassetcontent-endpoint-77bd29ce"}],"high":20,"name":"SiYuan","rank":9,"slug":"siyuan","score":148,"vendor":{"name":"SiYuan","slug":"siyuan"},"critical":10,"max_cvss":10,"max_epss":0.0103,"exploited":0,"vulnerabilities":58,"url":"https://junglewise.ai/threats/technologies/siyuan"},{"hub":true,"top":[{"cvss":9.8,"slug":"nltk-jvm-argument-injection-in-stanford-wrappers-via-per-call-options-628f3938","title":"NLTK JVM argument injection in Stanford wrappers via per-call options","severity":"critical","exploited":false,"published_at":"2026-08-25T18:31:52+00:00","url":"https://junglewise.ai/threats/nltk-jvm-argument-injection-in-stanford-wrappers-via-per-call-options-628f3938"},{"cve":"CVE-2026-79675","cvss":9.8,"epss":0.0078,"slug":"cve-2026-79675-nltk-jvm-argument-injection-bypass-in-stanford-wrappers","title":"NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to","severity":"critical","exploited":false,"published_at":"2026-08-25T16:17:28.013+00:00","url":"https://junglewise.ai/threats/cve-2026-79675-nltk-jvm-argument-injection-bypass-in-stanford-wrappers"},{"cvss":9.8,"slug":"nltk-unsafe-pickle-deserialization-in-allowlisted-loaders-eeef7a48","title":"NLTK unsafe pickle deserialization in allowlisted loaders","severity":"critical","exploited":false,"published_at":"2026-08-25T12:31:25+00:00","url":"https://junglewise.ai/threats/nltk-unsafe-pickle-deserialization-in-allowlisted-loaders-eeef7a48"}],"high":29,"name":"Pip Nltk","rank":10,"slug":"nltk","score":145,"vendor":{"name":"Pip","slug":"pip"},"critical":6,"max_cvss":9.8,"max_epss":0.0127,"exploited":0,"vulnerabilities":57,"url":"https://junglewise.ai/threats/technologies/nltk"},{"hub":true,"top":[{"cve":"CVE-2026-70478","cvss":10,"epss":0.0062,"slug":"cve-2026-70478-flowise-unauthenticated-oauth2-token-refresh-in-credential","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:54.61+00:00","url":"https://junglewise.ai/threats/cve-2026-70478-flowise-unauthenticated-oauth2-token-refresh-in-credential"},{"cve":"CVE-2026-70477","cvss":9.8,"epss":0.0081,"slug":"cve-2026-70477-flowise-rce-via-csv-agent-prompt-injection","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatfl","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:54.473+00:00","url":"https://junglewise.ai/threats/cve-2026-70477-flowise-rce-via-csv-agent-prompt-injection"},{"cve":"CVE-2026-70470","cvss":9.8,"epss":0.0097,"slug":"cve-2026-70470-flowise-pyodide-validator-unicode-homoglyph-bypass-in-csv-and","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFr","severity":"critical","exploited":false,"published_at":"2026-08-04T18:16:57.93+00:00","url":"https://junglewise.ai/threats/cve-2026-70470-flowise-pyodide-validator-unicode-homoglyph-bypass-in-csv-and"}],"high":17,"name":"Npm Flowise","rank":11,"slug":"flowise","score":124,"vendor":{"name":"Npm","slug":"npm"},"critical":11,"max_cvss":10,"max_epss":0.0274,"exploited":0,"vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise"},{"hub":true,"top":[{"cve":"CVE-2026-71164","cvss":9.8,"epss":0.0051,"slug":"cve-2026-71164-oracle-helidon-remote-code-execution-in-imperative-web-server","title":"Oracle Helidon remote code execution in Imperative Web Server","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:17.703+00:00","url":"https://junglewise.ai/threats/cve-2026-71164-oracle-helidon-remote-code-execution-in-imperative-web-server"},{"cve":"CVE-2026-71152","cvss":9.8,"epss":0.0051,"slug":"cve-2026-71152-oracle-helidon-remote-code-execution","title":"Oracle Helidon remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:16.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71152-oracle-helidon-remote-code-execution"},{"cve":"CVE-2026-71167","cvss":9.4,"epss":0.0046,"slug":"cve-2026-71167-oracle-helidon-unauthenticated-data-access-and-denial-of-service","title":"Oracle Helidon unauthenticated data access and denial of service","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:18.05+00:00","url":"https://junglewise.ai/threats/cve-2026-71167-oracle-helidon-unauthenticated-data-access-and-denial-of-service"}],"high":19,"name":"Oracle Helidon","rank":12,"slug":"helidon","score":123,"vendor":{"name":"Oracle","slug":"oracle"},"critical":6,"max_cvss":9.8,"max_epss":0.0051,"exploited":0,"vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/helidon"},{"hub":true,"top":[{"cve":"CVE-2026-70880","cvss":10,"epss":0.0051,"slug":"cve-2026-70880-oracle-hyperion-data-relationship-management-authentication","title":"Oracle Hyperion Data Relationship Management authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:44.49+00:00","url":"https://junglewise.ai/threats/cve-2026-70880-oracle-hyperion-data-relationship-management-authentication"},{"cve":"CVE-2026-70873","cvss":9.8,"epss":0.0051,"slug":"cve-2026-70873-oracle-hyperion-data-relationship-management-authentication","title":"Oracle Hyperion Data Relationship Management authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:43.607+00:00","url":"https://junglewise.ai/threats/cve-2026-70873-oracle-hyperion-data-relationship-management-authentication"},{"cve":"CVE-2026-70871","cvss":9.8,"epss":0.0051,"slug":"cve-2026-70871-oracle-hyperion-data-relationship-management-authentication","title":"Oracle Hyperion Data Relationship Management authentication bypass in access control","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:43.36+00:00","url":"https://junglewise.ai/threats/cve-2026-70871-oracle-hyperion-data-relationship-management-authentication"}],"high":26,"name":"Oracle Hyperion Data Relationship Management","rank":13,"slug":"hyperion-data-relationship-management","score":122,"vendor":{"name":"Oracle","slug":"oracle"},"critical":7,"max_cvss":10,"max_epss":0.0051,"exploited":0,"vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/hyperion-data-relationship-management"},{"hub":true,"top":[{"cve":"CVE-2026-65400","cvss":9.8,"epss":0.0122,"slug":"cve-2026-65400-apple-macos-screen-sharing-authentication-bypass","title":"An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, mac","severity":"critical","exploited":true,"published_at":"2026-08-06T22:18:14.533+00:00","url":"https://junglewise.ai/threats/cve-2026-65400-apple-macos-screen-sharing-authentication-bypass"},{"cve":"CVE-2026-79150","cvss":9.6,"epss":0.0046,"slug":"cve-2026-79150-google-chrome-use-after-free-in-views","title":"Google Chrome use-after-free in Views","severity":"critical","exploited":false,"published_at":"2026-08-25T21:18:10.27+00:00","url":"https://junglewise.ai/threats/cve-2026-79150-google-chrome-use-after-free-in-views"},{"cve":"CVE-2026-79140","cvss":9.6,"epss":0.0046,"slug":"cve-2026-79140-google-chrome-use-after-free-in-views-on-mac","title":"Google Chrome use after free in Views on Mac","severity":"critical","exploited":false,"published_at":"2026-08-25T21:18:09.273+00:00","url":"https://junglewise.ai/threats/cve-2026-79140-google-chrome-use-after-free-in-views-on-mac"}],"high":9,"name":"Apple macOS","rank":14,"slug":"macos-tahoe","score":117,"vendor":{"name":"Apple","slug":"apple"},"critical":8,"max_cvss":9.8,"max_epss":0.0122,"exploited":1,"vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-71037","cvss":9.3,"epss":0.0038,"slug":"cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http","title":"Oracle Commerce Guided Search remote code execution via HTTP","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.427+00:00","url":"https://junglewise.ai/threats/cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http"},{"cve":"CVE-2026-70998","cvss":9.3,"epss":0.0035,"slug":"cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access","title":"Oracle Commerce Guided Search remote unauthenticated data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:58.883+00:00","url":"https://junglewise.ai/threats/cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access"},{"cve":"CVE-2026-71036","cvss":9.1,"epss":0.0043,"slug":"cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access","title":"Oracle Commerce Experience Manager unauthorized data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.313+00:00","url":"https://junglewise.ai/threats/cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access"}],"high":21,"name":"Oracle Commerce Experience Manager","rank":15,"slug":"commerce-experience-manager","score":117,"vendor":{"name":"Oracle","slug":"oracle"},"critical":7,"max_cvss":9.3,"max_epss":0.0049,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/commerce-experience-manager"},{"hub":true,"top":[{"cve":"CVE-2026-71037","cvss":9.3,"epss":0.0038,"slug":"cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http","title":"Oracle Commerce Guided Search remote code execution via HTTP","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.427+00:00","url":"https://junglewise.ai/threats/cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http"},{"cve":"CVE-2026-70998","cvss":9.3,"epss":0.0035,"slug":"cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access","title":"Oracle Commerce Guided Search remote unauthenticated data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:58.883+00:00","url":"https://junglewise.ai/threats/cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access"},{"cve":"CVE-2026-71036","cvss":9.1,"epss":0.0043,"slug":"cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access","title":"Oracle Commerce Experience Manager unauthorized data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.313+00:00","url":"https://junglewise.ai/threats/cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access"}],"high":21,"name":"Oracle Commerce Guided Search","rank":16,"slug":"commerce-guided-search","score":117,"vendor":{"name":"Oracle","slug":"oracle"},"critical":7,"max_cvss":9.3,"max_epss":0.0049,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/commerce-guided-search"},{"hub":true,"top":[{"cvss":9.8,"slug":"nltk-jvm-argument-injection-in-stanford-wrappers-via-per-call-options-628f3938","title":"NLTK JVM argument injection in Stanford wrappers via per-call options","severity":"critical","exploited":false,"published_at":"2026-08-25T18:31:52+00:00","url":"https://junglewise.ai/threats/nltk-jvm-argument-injection-in-stanford-wrappers-via-per-call-options-628f3938"},{"cve":"CVE-2026-79675","cvss":9.8,"epss":0.0078,"slug":"cve-2026-79675-nltk-jvm-argument-injection-bypass-in-stanford-wrappers","title":"NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to","severity":"critical","exploited":false,"published_at":"2026-08-25T16:17:28.013+00:00","url":"https://junglewise.ai/threats/cve-2026-79675-nltk-jvm-argument-injection-bypass-in-stanford-wrappers"},{"cvss":9.8,"slug":"nltk-unsafe-pickle-deserialization-in-allowlisted-loaders-eeef7a48","title":"NLTK unsafe pickle deserialization in allowlisted loaders","severity":"critical","exploited":false,"published_at":"2026-08-25T12:31:25+00:00","url":"https://junglewise.ai/threats/nltk-unsafe-pickle-deserialization-in-allowlisted-loaders-eeef7a48"}],"high":21,"name":"NLTK Project Natural Language Toolkit","rank":17,"slug":"natural-language-toolkit","score":112,"vendor":{"name":"NLTK Project","slug":"nltk-project"},"critical":5,"max_cvss":9.8,"max_epss":0.011,"exploited":0,"vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/natural-language-toolkit"},{"hub":true,"top":[{"cve":"CVE-2026-78676","cvss":9.8,"epss":0.0078,"slug":"cve-2026-78676-gitpython-config-parser-multi-line-value-injection-in-write","title":"GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values","severity":"critical","exploited":false,"published_at":"2026-08-25T02:16:52.03+00:00","url":"https://junglewise.ai/threats/cve-2026-78676-gitpython-config-parser-multi-line-value-injection-in-write"},{"cvss":9.8,"slug":"gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b","title":"GitPython unsafe clone option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/gitpython-unsafe-clone-option-gate-bypass-through-joined-short-options-627f633b"},{"cve":"CVE-2026-67324","cvss":9.8,"epss":0.0064,"slug":"cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options","title":"GitPython unsafe option gate bypass through joined short options","severity":"critical","exploited":false,"published_at":"2026-08-01T13:17:02.77+00:00","url":"https://junglewise.ai/threats/cve-2026-67324-gitpython-unsafe-option-gate-bypass-through-joined-short-options"}],"high":26,"name":"Gitpython Project Gitpython","rank":18,"slug":"gitpython","score":107,"vendor":{"name":"Gitpython Project","slug":"gitpython-project"},"critical":3,"max_cvss":9.8,"max_epss":0.0221,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/gitpython"},{"hub":true,"top":[{"cve":"CVE-2026-70921","cvss":10,"epss":0.0043,"slug":"cve-2026-70921-oracle-hyperion-financial-management-authentication-bypass-in-tls","title":"Oracle Hyperion Financial Management authentication bypass in TLS","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:49.927+00:00","url":"https://junglewise.ai/threats/cve-2026-70921-oracle-hyperion-financial-management-authentication-bypass-in-tls"},{"cve":"CVE-2026-70920","cvss":9.9,"epss":0.0043,"slug":"cve-2026-70920-oracle-hyperion-financial-management-sql-injection-vulnerability","title":"Oracle Hyperion Financial Management SQL injection vulnerability in Security component","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:49.81+00:00","url":"https://junglewise.ai/threats/cve-2026-70920-oracle-hyperion-financial-management-sql-injection-vulnerability"},{"cve":"CVE-2026-70854","cvss":9.1,"epss":0.0045,"slug":"cve-2026-70854-oracle-hyperion-financial-management-authentication-bypass-in","title":"Oracle Hyperion Financial Management authentication bypass in Security component","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:41.48+00:00","url":"https://junglewise.ai/threats/cve-2026-70854-oracle-hyperion-financial-management-authentication-bypass-in"}],"high":18,"name":"Oracle Hyperion Financial Management","rank":19,"slug":"hyperion-financial-management","score":100,"vendor":{"name":"Oracle","slug":"oracle"},"critical":3,"max_cvss":10,"max_epss":0.0049,"exploited":0,"vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/hyperion-financial-management"},{"hub":true,"top":[{"cve":"CVE-2026-71958","cvss":9.8,"epss":0.0107,"slug":"cve-2026-71958-d-link-dwr-m961-buffer-overflow-in-quicksetup-cgi","title":"D-Link DWR-M961 buffer overflow in quicksetup.cgi","severity":"critical","exploited":false,"published_at":"2026-08-08T18:16:56.783+00:00","url":"https://junglewise.ai/threats/cve-2026-71958-d-link-dwr-m961-buffer-overflow-in-quicksetup-cgi"},{"cve":"CVE-2026-71957","cvss":9.8,"epss":0.0107,"slug":"cve-2026-71957-d-link-dwr-m961-buffer-overflow-in-app-cgi","title":"D-Link DWR-M961 buffer overflow in app.cgi","severity":"critical","exploited":false,"published_at":"2026-08-08T18:16:56.647+00:00","url":"https://junglewise.ai/threats/cve-2026-71957-d-link-dwr-m961-buffer-overflow-in-app-cgi"},{"cve":"CVE-2026-71956","cvss":9.8,"epss":0.0317,"slug":"cve-2026-71956-d-link-dwr-m961-command-injection-in-web-management-cgi","title":"D-Link DWR-M961 command injection in web-management CGI","severity":"critical","exploited":false,"published_at":"2026-08-08T18:16:56.503+00:00","url":"https://junglewise.ai/threats/cve-2026-71956-d-link-dwr-m961-command-injection-in-web-management-cgi"}],"high":0,"name":"D-Link DWR-M961","rank":20,"slug":"dwr-m961","score":90,"vendor":{"name":"D-Link","slug":"d-link"},"critical":15,"max_cvss":9.8,"max_epss":0.0317,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/dwr-m961"},{"hub":true,"top":[{"cve":"CVE-2026-71921","cvss":9.8,"epss":0.0279,"slug":"cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in","title":"DrayTek VigorSwitch pre-authentication command injection in setget.cgi","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:07.06+00:00","url":"https://junglewise.ai/threats/cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in"},{"cve":"CVE-2026-71933","cvss":9.1,"epss":0.0055,"slug":"cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions","title":"DrayTek VigorSwitch missing authorization in syslog functions","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:18.09+00:00","url":"https://junglewise.ai/threats/cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions"},{"cve":"CVE-2026-71922","cvss":7.5,"epss":0.0069,"slug":"cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi","title":"DrayTek VigorSwitch null pointer dereference in setget.cgi","severity":"high","exploited":false,"published_at":"2026-08-24T18:17:07.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi"}],"high":25,"name":"DrayTek VigorSwitch FX2120","rank":21,"slug":"vigorswitch-fx2120","score":89,"vendor":{"name":"DrayTek","slug":"draytek"},"critical":2,"max_cvss":9.8,"max_epss":0.0279,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/vigorswitch-fx2120"},{"hub":true,"top":[{"cve":"CVE-2026-71921","cvss":9.8,"epss":0.0279,"slug":"cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in","title":"DrayTek VigorSwitch pre-authentication command injection in setget.cgi","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:07.06+00:00","url":"https://junglewise.ai/threats/cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in"},{"cve":"CVE-2026-71933","cvss":9.1,"epss":0.0055,"slug":"cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions","title":"DrayTek VigorSwitch missing authorization in syslog functions","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:18.09+00:00","url":"https://junglewise.ai/threats/cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions"},{"cve":"CVE-2026-71922","cvss":7.5,"epss":0.0069,"slug":"cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi","title":"DrayTek VigorSwitch null pointer dereference in setget.cgi","severity":"high","exploited":false,"published_at":"2026-08-24T18:17:07.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi"}],"high":25,"name":"DrayTek VigorSwitch G1280","rank":22,"slug":"vigorswitch-g1280","score":89,"vendor":{"name":"DrayTek","slug":"draytek"},"critical":2,"max_cvss":9.8,"max_epss":0.0279,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/vigorswitch-g1280"},{"hub":true,"top":[{"cve":"CVE-2026-71921","cvss":9.8,"epss":0.0279,"slug":"cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in","title":"DrayTek VigorSwitch pre-authentication command injection in setget.cgi","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:07.06+00:00","url":"https://junglewise.ai/threats/cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in"},{"cve":"CVE-2026-71933","cvss":9.1,"epss":0.0055,"slug":"cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions","title":"DrayTek VigorSwitch missing authorization in syslog functions","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:18.09+00:00","url":"https://junglewise.ai/threats/cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions"},{"cve":"CVE-2026-71922","cvss":7.5,"epss":0.0069,"slug":"cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi","title":"DrayTek VigorSwitch null pointer dereference in setget.cgi","severity":"high","exploited":false,"published_at":"2026-08-24T18:17:07.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi"}],"high":25,"name":"DrayTek VigorSwitch G1282","rank":23,"slug":"vigorswitch-g1282","score":89,"vendor":{"name":"DrayTek","slug":"draytek"},"critical":2,"max_cvss":9.8,"max_epss":0.0279,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/vigorswitch-g1282"},{"hub":true,"top":[{"cve":"CVE-2026-71921","cvss":9.8,"epss":0.0279,"slug":"cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in","title":"DrayTek VigorSwitch pre-authentication command injection in setget.cgi","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:07.06+00:00","url":"https://junglewise.ai/threats/cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in"},{"cve":"CVE-2026-71933","cvss":9.1,"epss":0.0055,"slug":"cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions","title":"DrayTek VigorSwitch missing authorization in syslog functions","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:18.09+00:00","url":"https://junglewise.ai/threats/cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions"},{"cve":"CVE-2026-71922","cvss":7.5,"epss":0.0069,"slug":"cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi","title":"DrayTek VigorSwitch null pointer dereference in setget.cgi","severity":"high","exploited":false,"published_at":"2026-08-24T18:17:07.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi"}],"high":25,"name":"DrayTek VigorSwitch G2100","rank":24,"slug":"vigorswitch-g2100","score":89,"vendor":{"name":"DrayTek","slug":"draytek"},"critical":2,"max_cvss":9.8,"max_epss":0.0279,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/vigorswitch-g2100"},{"hub":true,"top":[{"cve":"CVE-2026-71921","cvss":9.8,"epss":0.0279,"slug":"cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in","title":"DrayTek VigorSwitch pre-authentication command injection in setget.cgi","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:07.06+00:00","url":"https://junglewise.ai/threats/cve-2026-71921-draytek-vigorswitch-pre-authentication-command-injection-in"},{"cve":"CVE-2026-71933","cvss":9.1,"epss":0.0055,"slug":"cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions","title":"DrayTek VigorSwitch missing authorization in syslog functions","severity":"critical","exploited":false,"published_at":"2026-08-24T18:17:18.09+00:00","url":"https://junglewise.ai/threats/cve-2026-71933-draytek-vigorswitch-missing-authorization-in-syslog-functions"},{"cve":"CVE-2026-71922","cvss":7.5,"epss":0.0069,"slug":"cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi","title":"DrayTek VigorSwitch null pointer dereference in setget.cgi","severity":"high","exploited":false,"published_at":"2026-08-24T18:17:07.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71922-draytek-vigorswitch-null-pointer-dereference-in-setget-cgi"}],"high":25,"name":"DrayTek VigorSwitch G2121","rank":25,"slug":"vigorswitch-g2121","score":89,"vendor":{"name":"DrayTek","slug":"draytek"},"critical":2,"max_cvss":9.8,"max_epss":0.0279,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/vigorswitch-g2121"}],"previous":{"key":"2026-07","top":"Microsoft Windows 11","period":{"end":"2026-07-31","start":"2026-07-01"},"totals":{"high":3223,"critical":782,"exploited":23,"technologies":4551,"vulnerabilities":10520},"url":"https://junglewise.ai/threats/monthly/2026-07"},"next":null}