Threat intelligence · updated hourly
Most vulnerable technologies, 20 to 26 September 2026
Updated . Rebuilt every hour.
In the 7 days from 20 September 2026 to 26 September 2026, Junglewise Threat Intelligence recorded 2,705 new vulnerabilities: 182 critical, 810 high and 4 exploited in the wild. The most vulnerable technology was Microsoft Windows, with 28 vulnerabilities (22 critical), followed by Linux Kernel (17) and mcp-atlassian (PyPI) (24).
- New vulnerabilities
- 2,705
- Critical
- 182
- Exploited in the wild
- 4
- Technologies affected
- 174
Ranking
Most affected vendors
- 1.Microsoft28 vulnerabilities, 22 critical, 0 exploited
- 2.Linux17 vulnerabilities, 16 critical, 0 exploited
- 3.Adobe13 vulnerabilities, 6 critical, 0 exploited
- 4.Apple9 vulnerabilities, 6 critical, 0 exploited
- 5.Klever6 vulnerabilities, 0 critical, 0 exploited
- 6.Moquette5 vulnerabilities, 1 critical, 0 exploited
- 7.Check Point1 vulnerability, 1 critical, 1 exploited
- 8.F51 vulnerability, 1 critical, 1 exploited
- 9.Wordpress1 vulnerability, 1 critical, 1 exploited
- 10.Dell8 vulnerabilities, 0 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-93952: VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…criticalexploited in the wildCVSS 10EPSS 0.9%
- CVE-2026-93616: A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary…criticalexploited in the wildCVSS 9.8EPSS 19.7%
- CVE-2026-94127: When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can…criticalexploited in the wildCVSS 9.8EPSS 2.2%
- CVE-2026-87902: An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php`…criticalexploited in the wildCVSS 8.1EPSS 2.9%
- CVE-2026-94097: A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file…criticalCVSS 10EPSS 2.9%
- CVE-2026-80155: Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1…criticalCVSS 10EPSS 1.7%
- CVE-2026-89275: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-84412: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-75721: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-75703: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
Technologies with the most tracked vulnerabilities
All time. Every vendor, and every technology of theirs with a page, is under vendors.
- Linux Kernel6,418
- Google Chrome2,529
- Microsoft Windows963
- Openclaw917
- Apple macOS906
- Microsoft Windows 10588
- Apple iPadOS501
- Microsoft Windows 11493
- Mozilla Firefox393
- Google Android356
- Mozilla Firefox ESR295
- Microsoft Windows Server 2012293
- Apple visionOS291
- Apple watchOS288
- Mozilla Thunderbird267
- Apple tvOS260
- N8n249
- Microsoft Windows Server 2016213
- Microsoft Windows Server 2019211
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP204
- WWBN AVideo195
- Microsoft Windows 11 24h2192
- Microsoft Windows Server 2022178
- Apple macOS Golden Gate172
- Microsoft Edge167
- Apple Iphone Os165
- Microsoft Windows 11 25h2161
- flowise (npm)156
- open-webui (PyPI)156
- SiYuan154
- Red Hat Enterprise Linux 9146
- Apple Safari141
- Red Hat Enterprise Linux 10140
- Microsoft Windows 11 Version 26H1135
- Red Hat Enterprise Linux 8132
- Oracle Hyperion Financial Management129
- Amazon AWS128
- Microsoft Windows Server 2025124
- GitLab Enterprise Edition116
- Microsoft Windows Server 2008116
- Oracle Coherence113
- Concrete CMS108
- ImageMagick108
- IBM AIX106
- Microsoft Windows 10 21h2105
- Microsoft Windows 10 22h2105
- Microsoft Office103
- Microsoft Windows 7100
- Microsoft Windows 8.1100
- IBM Langflow96
- Gitea89
- Snipeitapp Snipe-It89
- Microsoft Windows 10 180989
- Microsoft 365 Apps for Enterprise84
- Capgo83
- Oracle E-Business Suite83
- github.com/siyuan-note/siyuan/kernel (Go)83
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP83
- Oracle Commerce Guided Search82
- Microsoft Office LTSC 202182
- Microsoft Office LTSC 202482
- vm2 (npm)82
- Oracle Commerce Experience Manager81
- Elastic Kibana80
- Google Chrome for iOS79
- Microsoft Office 201979
- code.gitea.io/gitea (Go)76
- Langflow76
- Axios75
- Apple Multiple Products75
- Vercel Next.js75
- nltk (PyPI)74
- picklescan (PyPI)74
- Siemens SIMATIC CN 410074
- IBM PowerVM VIOS73
- Oracle WebCenter Content73
- Adobe ColdFusion70
- GitLab Community Edition70
- Huawei HarmonyOS70
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP70
- Oracle VirtualBox70
- Zephyr Project Zephyr70
- Cisco IOS69
- Mattermost Server69
- Oracle Helidon68
- Red Hat Enterprise Linux 767
- IBM i67
- Apache Tomcat67
- Microsoft Windows 10 160767
- FreeRDP66
- Open5GS66
- Mozilla Thunderbird-Esr66
- Microsoft SQL Server65
- Microsoft Windows Rt 8.165
- Microsoft Office 365 for Mac64
- Adobe Acrobat63
- getgrav/grav (Packagist)63
- Adobe Commerce62
- MongoDB Server62
- Apache Airflow61
- @budibase/server (npm)61
- Sitecore CMS61
- Adobe Acrobat Reader60
- directus (npm)60
- Oracle MySQL Server60
- OpenSSL59
- surrealdb (crates.io)59
- Discourse58
- wwbn/avideo (Packagist)58
- NLTK Project Natural Language Toolkit57
- SourceCodester Class and Exam Timetabling System56
- Adobe Flash Player56
- Gitpython Project Gitpython56
- Oracle Hyperion Data Relationship Management56
- Magick.NET-Q16-AnyCPU (NuGet)56
- Thorsten phpMyFAQ56
- Dell Secure Connect Gateway Appliance56
- Dell Secure Connect Gateway Application56
- Adobe AIR55
- Red Hat Enterprise Linux 655
- Grav55
- nocodb (npm)55
- Oracle WebLogic Server55
- Fortinet FortiOS54
- hono (npm)54
- Sgi IRIX54
- Red Hat Build of Keycloak54
- IBM WebSphere Application Server54
- Cisco IOS XE53
- Keycloak53
- Microsoft Exchange Server52
- Oracle Java SE52
- Magick.NET-Q16-HDRI-AnyCPU (NuGet)52
- Magick.NET-Q16-HDRI-x86 (NuGet)52
- Magick.NET-Q16-x86 (NuGet)52
- Coollabs Coolify51
- Arubanetworks Fabric Composer51
- Cisco Identity Services Engine51
- Magick.NET-Q8-AnyCPU (NuGet)51
- Magick.NET-Q8-OpenMP-x64 (NuGet)51
- Magick.NET-Q8-x86 (NuGet)51
- Hpe Networking Fabric Composer51
- Magick.NET-Q16-OpenMP-x64 (NuGet)50
- Arista EOS49
- FreeBSD49
- Microsoft Internet Explorer49
- Magick.NET-Q16-arm64 (NuGet)49
- Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet)49
- Magick.NET-Q16-HDRI-x64 (NuGet)49
- Magick.NET-Q16-OpenMP-arm64 (NuGet)49
- Magick.NET-Q16-x64 (NuGet)49
- Magick.NET-Q8-x64 (NuGet)49
- Oracle MySQL Cluster49
- Microsoft Office Excel49
- Microsoft Office Word49
- Red Hat Keycloak48
- Magick.NET-Q16-HDRI-arm64 (NuGet)48
- Magick.NET-Q8-arm64 (NuGet)48
- Magick.NET-Q8-OpenMP-arm64 (NuGet)48
- openbabel (PyPI)48
- FFmpeg47
- GPAC47
- Erlang OTP47
- Open ISES Tickets47
- concrete5/concrete5 (Packagist)46
- Craft CMS46
- Red Hat Enterprise Linux AppStream46
- Debian GNU/Linux45
- Watchguard Fireware OS45
- Microsoft Office LTSC for Mac 202145
- Microsoft Office LTSC for Mac 202445
- Oracle Advanced Outbound Telephony44
- apache-superset (PyPI)44
- wolfSSL44
- Haxx Curl43
- Nvidia Megatron-Bridge43
- Jetbrains YouTrack43
- MB connect line mbCONNECT2442
- MB connect line mymbCONNECT2442
- parse-server (npm)42
- NLnet Labs Unbound42
- Microsoft Windows Vista42
- F5 BIG-IP41
- Google Chromium V841
- Tcpdump41
- Oracle WebCenter Portal41
- Roundcube Webmail41
- apache-airflow (PyPI)40
- Apache Camel40
- Itsourcecode Hospital Management System40
- Microsoft Office 201640
- Dell Secure Connect Gateway 5.0 Appliance40
- Dell Secure Connect Gateway 5.0 Application40
- Microsoft Windows 11 23h240
- Xen Project Xen40
- Adobe Acrobat DC39
- dompurify (npm)39
- ghost (npm)39
- snipe/snipe-it (Packagist)39
- Apache Traffic Server39
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies, 20 to 26 September 2026", https://junglewise.ai/threats/technologies, 26 September 2026.