{"schema_version":1,"title":"Most vulnerable technologies, 20 to 26 September 2026","summary":"In the 7 days from 20 September 2026 to 26 September 2026, Junglewise Threat Intelligence recorded 2,707 new vulnerabilities: 182 critical, 810 high and 4 exploited in the wild. The most vulnerable technology was Linux Kernel, with 606 vulnerabilities (20 critical), followed by Microsoft Windows (28) and mcp-atlassian (PyPI) (24).","url":"https://junglewise.ai/threats/technologies","json_url":"https://junglewise.ai/threats/technologies.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"live","period":{"end":"2026-09-26","start":"2026-09-20"},"totals":{"high":810,"critical":182,"exploited":4,"technologies":505,"vulnerabilities":2707},"notable":[{"cve":"CVE-2026-93952","cvss":10,"epss":0.009,"slug":"cve-2026-93952-arista-velocloud-orchestrator-improper-input-validation","title":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functio","severity":"critical","exploited":true,"published_at":"2026-09-22T08:16:43.047+00:00","url":"https://junglewise.ai/threats/cve-2026-93952-arista-velocloud-orchestrator-improper-input-validation"},{"cve":"CVE-2026-93616","cvss":9.8,"epss":0.1965,"slug":"cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability","title":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Poin","severity":"critical","exploited":true,"published_at":"2026-09-22T13:17:11.963+00:00","url":"https://junglewise.ai/threats/cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability"},{"cve":"CVE-2026-94127","cvss":9.8,"epss":0.0223,"slug":"cve-2026-94127-f5-big-ip-apm-heap-based-buffer-overflow","title":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code","severity":"critical","exploited":true,"published_at":"2026-09-22T15:17:24.313+00:00","url":"https://junglewise.ai/threats/cve-2026-94127-f5-big-ip-apm-heap-based-buffer-overflow"},{"cve":"CVE-2026-87902","cvss":8.1,"epss":0.0288,"slug":"cve-2026-87902-wordpress-core-remote-file-inclusion","title":"An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the","severity":"critical","exploited":true,"published_at":"2026-09-22T17:17:28.31+00:00","url":"https://junglewise.ai/threats/cve-2026-87902-wordpress-core-remote-file-inclusion"},{"cve":"CVE-2026-94097","cvss":10,"epss":0.0294,"slug":"cve-2026-94097-a-vulnerability-was-determined-in-netcore-nbr200v2-1-3-241127","title":"A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of","severity":"critical","exploited":false,"published_at":"2026-09-21T00:16:59.793+00:00","url":"https://junglewise.ai/threats/cve-2026-94097-a-vulnerability-was-determined-in-netcore-nbr200v2-1-3-241127"},{"cve":"CVE-2026-80155","cvss":10,"epss":0.0167,"slug":"cve-2026-80155-lantronix-slc8000-before-firmware-v9-7-0-5-slc9000-before","title":"Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware ver","severity":"critical","exploited":false,"published_at":"2026-09-22T16:18:01.917+00:00","url":"https://junglewise.ai/threats/cve-2026-80155-lantronix-slc8000-before-firmware-v9-7-0-5-slc9000-before"},{"cve":"CVE-2026-89275","cvss":10,"epss":0.0125,"slug":"cve-2026-89275-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:29.407+00:00","url":"https://junglewise.ai/threats/cve-2026-89275-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"},{"cve":"CVE-2026-84412","cvss":10,"epss":0.0125,"slug":"cve-2026-84412-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:22.923+00:00","url":"https://junglewise.ai/threats/cve-2026-84412-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"},{"cve":"CVE-2026-75721","cvss":10,"epss":0.0125,"slug":"cve-2026-75721-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:16.033+00:00","url":"https://junglewise.ai/threats/cve-2026-75721-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"},{"cve":"CVE-2026-75703","cvss":10,"epss":0.0125,"slug":"cve-2026-75703-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:15.9+00:00","url":"https://junglewise.ai/threats/cve-2026-75703-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"}],"vendors":[{"hub":true,"high":125,"name":"Linux","rank":1,"slug":"linux","critical":20,"exploited":0,"vulnerabilities":588,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":6,"name":"Microsoft","rank":2,"slug":"microsoft","critical":22,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":19,"name":"IBM","rank":3,"slug":"ibm","critical":4,"exploited":0,"vulnerabilities":27,"url":"https://junglewise.ai/threats/vendors/ibm"},{"hub":true,"high":10,"name":"Adobe","rank":4,"slug":"adobe","critical":6,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/vendors/adobe"},{"hub":true,"high":1,"name":"Apple","rank":5,"slug":"apple","critical":6,"exploited":0,"vulnerabilities":9,"url":"https://junglewise.ai/threats/vendors/apple"},{"hub":true,"high":6,"name":"Apache","rank":6,"slug":"apache","critical":2,"exploited":0,"vulnerabilities":14,"url":"https://junglewise.ai/threats/vendors/apache"},{"hub":true,"high":0,"name":"Zammad","rank":7,"slug":"zammad","critical":0,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/vendors/zammad"},{"hub":true,"high":6,"name":"Dell","rank":8,"slug":"dell","critical":0,"exploited":0,"vulnerabilities":13,"url":"https://junglewise.ai/threats/vendors/dell"},{"hub":false,"high":5,"name":"Botslab","rank":9,"slug":"botslab","critical":0,"exploited":0,"vulnerabilities":14},{"hub":false,"high":3,"name":"InvoicePlane","rank":10,"slug":"invoiceplane","critical":1,"exploited":0,"vulnerabilities":13}],"directory":[{"name":"Linux Kernel","slug":"kernel","vulnerabilities":6418,"url":"https://junglewise.ai/threats/technologies/kernel"},{"name":"Google Chrome","slug":"chrome","vulnerabilities":2529,"url":"https://junglewise.ai/threats/technologies/chrome"},{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":963,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Openclaw","slug":"openclaw","vulnerabilities":917,"url":"https://junglewise.ai/threats/technologies/openclaw"},{"name":"Apple macOS","slug":"macos-tahoe","vulnerabilities":906,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Apple iPadOS","slug":"ipados","vulnerabilities":501,"url":"https://junglewise.ai/threats/technologies/ipados"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Mozilla Firefox","slug":"firefox","vulnerabilities":393,"url":"https://junglewise.ai/threats/technologies/firefox"},{"name":"Google Android","slug":"android","vulnerabilities":356,"url":"https://junglewise.ai/threats/technologies/android"},{"name":"Mozilla Firefox ESR","slug":"firefox-esr","vulnerabilities":295,"url":"https://junglewise.ai/threats/technologies/firefox-esr"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Apple visionOS","slug":"visionos","vulnerabilities":291,"url":"https://junglewise.ai/threats/technologies/visionos"},{"name":"Apple watchOS","slug":"watchos","vulnerabilities":288,"url":"https://junglewise.ai/threats/technologies/watchos"},{"name":"Mozilla Thunderbird","slug":"thunderbird","vulnerabilities":267,"url":"https://junglewise.ai/threats/technologies/thunderbird"},{"name":"Apple tvOS","slug":"tvos","vulnerabilities":260,"url":"https://junglewise.ai/threats/technologies/tvos"},{"name":"N8n","slug":"n8n","vulnerabilities":249,"url":"https://junglewise.ai/threats/technologies/n8n"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":204,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"WWBN AVideo","slug":"avideo","vulnerabilities":195,"url":"https://junglewise.ai/threats/technologies/avideo"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Apple macOS Golden Gate","slug":"macos-golden-gate","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/macos-golden-gate"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":167,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Apple Iphone Os","slug":"iphone-os","vulnerabilities":165,"url":"https://junglewise.ai/threats/technologies/iphone-os"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"SiYuan","slug":"siyuan","vulnerabilities":154,"url":"https://junglewise.ai/threats/technologies/siyuan"},{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Apple Safari","slug":"safari","vulnerabilities":141,"url":"https://junglewise.ai/threats/technologies/safari"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Oracle Hyperion Financial Management","slug":"hyperion-financial-management","vulnerabilities":129,"url":"https://junglewise.ai/threats/technologies/hyperion-financial-management"},{"name":"Amazon AWS","slug":"aws","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/aws"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"},{"name":"GitLab Enterprise Edition","slug":"gitlab-ee","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/gitlab-ee"},{"name":"Microsoft Windows Server 2008","slug":"windows-server-2008","vulnerabilities":116,"url":"https://junglewise.ai/threats/technologies/windows-server-2008"},{"name":"Oracle Coherence","slug":"coherence","vulnerabilities":113,"url":"https://junglewise.ai/threats/technologies/coherence"},{"name":"Concrete CMS","slug":"concrete-cms","vulnerabilities":108,"url":"https://junglewise.ai/threats/technologies/concrete-cms"},{"name":"ImageMagick","slug":"imagemagick","vulnerabilities":108,"url":"https://junglewise.ai/threats/technologies/imagemagick"},{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"Microsoft Windows 10 21h2","slug":"windows-10-21h2","vulnerabilities":105,"url":"https://junglewise.ai/threats/technologies/windows-10-21h2"},{"name":"Microsoft Windows 10 22h2","slug":"windows-10-22h2","vulnerabilities":105,"url":"https://junglewise.ai/threats/technologies/windows-10-22h2"},{"name":"Microsoft Office","slug":"office","vulnerabilities":103,"url":"https://junglewise.ai/threats/technologies/office"},{"name":"Microsoft Windows 7","slug":"windows-7","vulnerabilities":100,"url":"https://junglewise.ai/threats/technologies/windows-7"},{"name":"Microsoft Windows 8.1","slug":"windows-8-1","vulnerabilities":100,"url":"https://junglewise.ai/threats/technologies/windows-8-1"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"Gitea","slug":"gitea","vulnerabilities":89,"url":"https://junglewise.ai/threats/technologies/gitea"},{"name":"Snipeitapp Snipe-It","slug":"snipe-it","vulnerabilities":89,"url":"https://junglewise.ai/threats/technologies/snipe-it"},{"name":"Microsoft Windows 10 1809","slug":"windows-10-1809","vulnerabilities":89,"url":"https://junglewise.ai/threats/technologies/windows-10-1809"},{"name":"Microsoft 365 Apps for Enterprise","slug":"365-apps-for-enterprise","vulnerabilities":84,"url":"https://junglewise.ai/threats/technologies/365-apps-for-enterprise"},{"name":"Capgo","slug":"capgo","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/capgo"},{"name":"Oracle E-Business Suite","slug":"e-business-suite","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/e-business-suite"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","slug":"simatic-s7-1500-cpu-1518f-4-pn-dp-mfp","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/simatic-s7-1500-cpu-1518f-4-pn-dp-mfp"},{"name":"Oracle Commerce Guided Search","slug":"commerce-guided-search","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/commerce-guided-search"},{"name":"Microsoft Office LTSC 2021","slug":"office-ltsc-2021","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/office-ltsc-2021"},{"name":"Microsoft Office LTSC 2024","slug":"office-ltsc-2024","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/office-ltsc-2024"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"Oracle Commerce Experience Manager","slug":"commerce-experience-manager","vulnerabilities":81,"url":"https://junglewise.ai/threats/technologies/commerce-experience-manager"},{"name":"Elastic Kibana","slug":"kibana","vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/kibana"},{"name":"Google Chrome for iOS","slug":"chrome-for-ios","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/chrome-for-ios"},{"name":"Microsoft Office 2019","slug":"office-2019","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/office-2019"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"Langflow","slug":"langflow","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/langflow"},{"name":"Axios","slug":"axios","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/axios"},{"name":"Apple Multiple Products","slug":"multiple-products","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/multiple-products"},{"name":"Vercel Next.js","slug":"next-js","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/next-js"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"Siemens SIMATIC CN 4100","slug":"simatic-cn-4100","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/simatic-cn-4100"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"Oracle WebCenter Content","slug":"webcenter-content","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/webcenter-content"},{"name":"Adobe ColdFusion","slug":"coldfusion","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/coldfusion"},{"name":"GitLab Community Edition","slug":"gitlab-ce","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/gitlab-ce"},{"name":"Huawei HarmonyOS","slug":"harmonyos","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/harmonyos"},{"name":"Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","slug":"siplus-s7-1500-cpu-1518-4-pn-dp-mfp","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/siplus-s7-1500-cpu-1518-4-pn-dp-mfp"},{"name":"Oracle VirtualBox","slug":"virtualbox","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/virtualbox"},{"name":"Zephyr Project Zephyr","slug":"zephyr","vulnerabilities":70,"url":"https://junglewise.ai/threats/technologies/zephyr"},{"name":"Cisco IOS","slug":"ios","vulnerabilities":69,"url":"https://junglewise.ai/threats/technologies/ios"},{"name":"Mattermost Server","slug":"server-public","vulnerabilities":69,"url":"https://junglewise.ai/threats/technologies/server-public"},{"name":"Oracle Helidon","slug":"helidon","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/helidon"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"IBM i","slug":"i","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Microsoft Windows 10 1607","slug":"windows-10-1607","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/windows-10-1607"},{"name":"FreeRDP","slug":"freerdp","vulnerabilities":66,"url":"https://junglewise.ai/threats/technologies/freerdp"},{"name":"Open5GS","slug":"open5gs","vulnerabilities":66,"url":"https://junglewise.ai/threats/technologies/open5gs"},{"name":"Mozilla Thunderbird-Esr","slug":"thunderbird-esr","vulnerabilities":66,"url":"https://junglewise.ai/threats/technologies/thunderbird-esr"},{"name":"Microsoft SQL Server","slug":"sql-server","vulnerabilities":65,"url":"https://junglewise.ai/threats/technologies/sql-server"},{"name":"Microsoft Windows Rt 8.1","slug":"windows-rt-8-1","vulnerabilities":65,"url":"https://junglewise.ai/threats/technologies/windows-rt-8-1"},{"name":"Microsoft Office 365 for Mac","slug":"office-365-for-mac","vulnerabilities":64,"url":"https://junglewise.ai/threats/technologies/office-365-for-mac"},{"name":"Adobe Acrobat","slug":"acrobat","vulnerabilities":63,"url":"https://junglewise.ai/threats/technologies/acrobat"},{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":63,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"Adobe Commerce","slug":"commerce","vulnerabilities":62,"url":"https://junglewise.ai/threats/technologies/commerce"},{"name":"MongoDB Server","slug":"mongodb-server","vulnerabilities":62,"url":"https://junglewise.ai/threats/technologies/mongodb-server"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"Sitecore CMS","slug":"cms","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/cms"},{"name":"Adobe Acrobat Reader","slug":"acrobat-reader","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/acrobat-reader"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"Oracle MySQL Server","slug":"mysql-server","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/mysql-server"},{"name":"OpenSSL","slug":"openssl","vulnerabilities":59,"url":"https://junglewise.ai/threats/technologies/openssl"},{"name":"surrealdb (crates.io)","slug":"surrealdb","vulnerabilities":59,"url":"https://junglewise.ai/threats/technologies/surrealdb"},{"name":"Discourse","slug":"discourse","vulnerabilities":58,"url":"https://junglewise.ai/threats/technologies/discourse"},{"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vulnerabilities":58,"url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},{"name":"NLTK Project Natural Language Toolkit","slug":"natural-language-toolkit","vulnerabilities":57,"url":"https://junglewise.ai/threats/technologies/natural-language-toolkit"},{"name":"SourceCodester Class and Exam Timetabling System","slug":"class-and-exam-timetabling-system","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/class-and-exam-timetabling-system"},{"name":"Adobe Flash Player","slug":"flash-player","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/flash-player"},{"name":"Gitpython Project Gitpython","slug":"gitpython","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/gitpython"},{"name":"Oracle Hyperion Data Relationship Management","slug":"hyperion-data-relationship-management","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/hyperion-data-relationship-management"},{"name":"Magick.NET-Q16-AnyCPU (NuGet)","slug":"magick-net-q16-anycpu","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-anycpu"},{"name":"Thorsten phpMyFAQ","slug":"phpmyfaq","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/phpmyfaq"},{"name":"Dell Secure Connect Gateway Appliance","slug":"secure-connect-gateway-appliance","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-appliance"},{"name":"Dell Secure Connect Gateway Application","slug":"secure-connect-gateway-application","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-application"},{"name":"Adobe AIR","slug":"air","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/air"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Grav","slug":"grav","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/grav"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"Oracle WebLogic Server","slug":"weblogic-server","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/weblogic-server"},{"name":"Fortinet FortiOS","slug":"fortios","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/fortios"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"Sgi IRIX","slug":"irix","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/irix"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"Cisco IOS XE","slug":"ios-xe","vulnerabilities":53,"url":"https://junglewise.ai/threats/technologies/ios-xe"},{"name":"Keycloak","slug":"keycloak","vulnerabilities":53,"url":"https://junglewise.ai/threats/technologies/keycloak"},{"name":"Microsoft Exchange Server","slug":"exchange-server","vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/exchange-server"},{"name":"Oracle Java SE","slug":"java-se","vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/java-se"},{"name":"Magick.NET-Q16-HDRI-AnyCPU (NuGet)","slug":"magick-net-q16-hdri-anycpu","vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-hdri-anycpu"},{"name":"Magick.NET-Q16-HDRI-x86 (NuGet)","slug":"magick-net-q16-hdri-x86","vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-hdri-x86"},{"name":"Magick.NET-Q16-x86 (NuGet)","slug":"magick-net-q16-x86","vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-x86"},{"name":"Coollabs Coolify","slug":"coolify","vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/coolify"},{"name":"Arubanetworks Fabric Composer","slug":"fabric-composer","vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/fabric-composer"},{"name":"Cisco Identity Services Engine","slug":"identity-services-engine","vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/identity-services-engine"},{"name":"Magick.NET-Q8-AnyCPU (NuGet)","slug":"magick-net-q8-anycpu","vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/magick-net-q8-anycpu"},{"name":"Magick.NET-Q8-OpenMP-x64 (NuGet)","slug":"magick-net-q8-openmp-x64","vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/magick-net-q8-openmp-x64"},{"name":"Magick.NET-Q8-x86 (NuGet)","slug":"magick-net-q8-x86","vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/magick-net-q8-x86"},{"name":"Hpe Networking Fabric Composer","slug":"networking-fabric-composer","vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/networking-fabric-composer"},{"name":"Magick.NET-Q16-OpenMP-x64 (NuGet)","slug":"magick-net-q16-openmp-x64","vulnerabilities":50,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-openmp-x64"},{"name":"Arista EOS","slug":"eos","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/eos"},{"name":"FreeBSD","slug":"freebsd","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/freebsd"},{"name":"Microsoft Internet Explorer","slug":"internet-explorer","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/internet-explorer"},{"name":"Magick.NET-Q16-arm64 (NuGet)","slug":"magick-net-q16-arm64","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-arm64"},{"name":"Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet)","slug":"magick-net-q16-hdri-openmp-arm64","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-hdri-openmp-arm64"},{"name":"Magick.NET-Q16-HDRI-x64 (NuGet)","slug":"magick-net-q16-hdri-x64","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-hdri-x64"},{"name":"Magick.NET-Q16-OpenMP-arm64 (NuGet)","slug":"magick-net-q16-openmp-arm64","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-openmp-arm64"},{"name":"Magick.NET-Q16-x64 (NuGet)","slug":"magick-net-q16-x64","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-x64"},{"name":"Magick.NET-Q8-x64 (NuGet)","slug":"magick-net-q8-x64","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/magick-net-q8-x64"},{"name":"Oracle MySQL Cluster","slug":"mysql-cluster","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/mysql-cluster"},{"name":"Microsoft Office Excel","slug":"office-excel","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/office-excel"},{"name":"Microsoft Office Word","slug":"office-word","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/office-word"},{"name":"Red Hat Keycloak","slug":"build-of-keycloak","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/build-of-keycloak"},{"name":"Magick.NET-Q16-HDRI-arm64 (NuGet)","slug":"magick-net-q16-hdri-arm64","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/magick-net-q16-hdri-arm64"},{"name":"Magick.NET-Q8-arm64 (NuGet)","slug":"magick-net-q8-arm64","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/magick-net-q8-arm64"},{"name":"Magick.NET-Q8-OpenMP-arm64 (NuGet)","slug":"magick-net-q8-openmp-arm64","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/magick-net-q8-openmp-arm64"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"FFmpeg","slug":"ffmpeg","vulnerabilities":47,"url":"https://junglewise.ai/threats/technologies/ffmpeg"},{"name":"GPAC","slug":"gpac","vulnerabilities":47,"url":"https://junglewise.ai/threats/technologies/gpac"},{"name":"Erlang OTP","slug":"otp","vulnerabilities":47,"url":"https://junglewise.ai/threats/technologies/otp"},{"name":"Open ISES Tickets","slug":"tickets","vulnerabilities":47,"url":"https://junglewise.ai/threats/technologies/tickets"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"Craft CMS","slug":"craft-cms","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/craft-cms"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Debian GNU/Linux","slug":"debian","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/debian"},{"name":"Watchguard Fireware OS","slug":"fireware-os","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/fireware-os"},{"name":"Microsoft Office LTSC for Mac 2021","slug":"office-ltsc-for-mac-2021","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/office-ltsc-for-mac-2021"},{"name":"Microsoft Office LTSC for Mac 2024","slug":"office-ltsc-for-mac-2024","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/office-ltsc-for-mac-2024"},{"name":"Oracle Advanced Outbound Telephony","slug":"advanced-outbound-telephony","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/advanced-outbound-telephony"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"wolfSSL","slug":"wolfssl","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/wolfssl"},{"name":"Haxx Curl","slug":"curl","vulnerabilities":43,"url":"https://junglewise.ai/threats/technologies/curl"},{"name":"Nvidia Megatron-Bridge","slug":"megatron-bridge","vulnerabilities":43,"url":"https://junglewise.ai/threats/technologies/megatron-bridge"},{"name":"Jetbrains YouTrack","slug":"youtrack","vulnerabilities":43,"url":"https://junglewise.ai/threats/technologies/youtrack"},{"name":"MB connect line mbCONNECT24","slug":"mbconnect24","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/mbconnect24"},{"name":"MB connect line mymbCONNECT24","slug":"mymbconnect24","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/mymbconnect24"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"NLnet Labs Unbound","slug":"unbound","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/unbound"},{"name":"Microsoft Windows Vista","slug":"windows-vista","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/windows-vista"},{"name":"F5 BIG-IP","slug":"big-ip","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/big-ip"},{"name":"Google Chromium V8","slug":"chromium-v8","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/chromium-v8"},{"name":"Tcpdump","slug":"tcpdump","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/tcpdump"},{"name":"Oracle WebCenter Portal","slug":"webcenter-portal","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/webcenter-portal"},{"name":"Roundcube Webmail","slug":"webmail","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/webmail"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Itsourcecode Hospital Management System","slug":"hospital-management-system","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/hospital-management-system"},{"name":"Microsoft Office 2016","slug":"office-2016","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/office-2016"},{"name":"Dell Secure Connect Gateway 5.0 Appliance","slug":"secure-connect-gateway-5-0-appliance","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-5-0-appliance"},{"name":"Dell Secure Connect Gateway 5.0 Application","slug":"secure-connect-gateway-5-0-application","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-5-0-application"},{"name":"Microsoft Windows 11 23h2","slug":"windows-11-23h2","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/windows-11-23h2"},{"name":"Xen Project Xen","slug":"xen","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/xen"},{"name":"Adobe Acrobat DC","slug":"acrobat-dc","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/acrobat-dc"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"}],"last_week":"2026-09-14","last_month":"2026-08","generated_at":"2026-09-26T11:07:00.153785+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-89275","cvss":10,"epss":0.0125,"slug":"cve-2026-89275-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:29.407+00:00","url":"https://junglewise.ai/threats/cve-2026-89275-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"},{"cve":"CVE-2026-84412","cvss":10,"epss":0.0125,"slug":"cve-2026-84412-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:22.923+00:00","url":"https://junglewise.ai/threats/cve-2026-84412-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"},{"cve":"CVE-2026-75723","cvss":10,"epss":0.0117,"slug":"cve-2026-75723-adobe-campaign-classic-acc-is-affected-by-an-incorrect","title":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the co","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:16.163+00:00","url":"https://junglewise.ai/threats/cve-2026-75723-adobe-campaign-classic-acc-is-affected-by-an-incorrect"}],"high":126,"name":"Linux Kernel","rank":1,"slug":"kernel","score":958,"vendor":{"name":"Linux","slug":"linux"},"critical":20,"max_cvss":10,"max_epss":0.0125,"exploited":0,"vulnerabilities":606,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-89275","cvss":10,"epss":0.0125,"slug":"cve-2026-89275-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:29.407+00:00","url":"https://junglewise.ai/threats/cve-2026-89275-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"},{"cve":"CVE-2026-84412","cvss":10,"epss":0.0125,"slug":"cve-2026-84412-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of","title":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:22.923+00:00","url":"https://junglewise.ai/threats/cve-2026-84412-adobe-campaign-classic-acc-is-affected-by-an-improper-control-of"},{"cve":"CVE-2026-75723","cvss":10,"epss":0.0117,"slug":"cve-2026-75723-adobe-campaign-classic-acc-is-affected-by-an-incorrect","title":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the co","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:16.163+00:00","url":"https://junglewise.ai/threats/cve-2026-75723-adobe-campaign-classic-acc-is-affected-by-an-incorrect"}],"high":4,"name":"Microsoft Windows","rank":2,"slug":"windows-","score":146,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":22,"max_cvss":10,"max_epss":0.0125,"exploited":0,"vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2026-77244","cvss":10,"epss":0.0028,"slug":"cve-2026-77244-mcp-atlassian-authentication-bypass-in-http-transport","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport acc","severity":"critical","exploited":false,"published_at":"2026-09-22T18:17:17.56+00:00","url":"https://junglewise.ai/threats/cve-2026-77244-mcp-atlassian-authentication-bypass-in-http-transport"},{"cve":"CVE-2026-77243","cvss":8.8,"epss":0.0036,"slug":"cve-2026-77243-mcp-atlassian-tool-authorization-bypass-in-tools-call","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOL","severity":"high","exploited":false,"published_at":"2026-09-22T18:17:17.41+00:00","url":"https://junglewise.ai/threats/cve-2026-77243-mcp-atlassian-tool-authorization-bypass-in-tools-call"},{"cve":"CVE-2026-77262","cvss":8.6,"epss":0.0054,"slug":"cve-2026-77262-sooperset-mcp-atlassian-path-traversal-in-confluence-upload","title":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_atta","severity":"high","exploited":false,"published_at":"2026-09-22T19:16:50.48+00:00","url":"https://junglewise.ai/threats/cve-2026-77262-sooperset-mcp-atlassian-path-traversal-in-confluence-upload"}],"high":15,"name":"mcp-atlassian (PyPI)","rank":3,"slug":"mcp-atlassian","score":59,"vendor":{"name":"PyPI","slug":"pypi"},"critical":1,"max_cvss":10,"max_epss":0.0054,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"hub":false,"top":[{"cve":"CVE-2026-75682","cvss":9.9,"epss":0.0054,"slug":"cve-2026-75682-adobe-connect-is-affected-by-an-improper-neutralization-of","title":"Adobe Connect SQL injection leading to arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.26+00:00","url":"https://junglewise.ai/threats/cve-2026-75682-adobe-connect-is-affected-by-an-improper-neutralization-of"},{"cve":"CVE-2026-75698","cvss":9.3,"epss":0.0032,"slug":"cve-2026-75698-adobe-connect-is-affected-by-a-reflected-cross-site-scripting-xss","title":"Adobe Connect reflected Cross-Site Scripting in web page","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.91+00:00","url":"https://junglewise.ai/threats/cve-2026-75698-adobe-connect-is-affected-by-a-reflected-cross-site-scripting-xss"},{"cve":"CVE-2026-75697","cvss":9.3,"epss":0.003,"slug":"cve-2026-75697-adobe-connect-is-affected-by-a-stored-cross-site-scripting-xss","title":"Adobe Connect stored cross-site scripting in form fields","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.77+00:00","url":"https://junglewise.ai/threats/cve-2026-75697-adobe-connect-is-affected-by-a-stored-cross-site-scripting-xss"}],"high":1,"name":"Adobe Connect","rank":4,"slug":"adobe-connect","score":41,"vendor":{"name":"Adobe","slug":"adobe"},"critical":6,"max_cvss":9.9,"max_epss":0.0105,"exploited":0,"vulnerabilities":9},{"hub":true,"top":[{"cve":"CVE-2026-75682","cvss":9.9,"epss":0.0054,"slug":"cve-2026-75682-adobe-connect-is-affected-by-an-improper-neutralization-of","title":"Adobe Connect SQL injection leading to arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.26+00:00","url":"https://junglewise.ai/threats/cve-2026-75682-adobe-connect-is-affected-by-an-improper-neutralization-of"},{"cve":"CVE-2026-75698","cvss":9.3,"epss":0.0032,"slug":"cve-2026-75698-adobe-connect-is-affected-by-a-reflected-cross-site-scripting-xss","title":"Adobe Connect reflected Cross-Site Scripting in web page","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.91+00:00","url":"https://junglewise.ai/threats/cve-2026-75698-adobe-connect-is-affected-by-a-reflected-cross-site-scripting-xss"},{"cve":"CVE-2026-75697","cvss":9.3,"epss":0.003,"slug":"cve-2026-75697-adobe-connect-is-affected-by-a-stored-cross-site-scripting-xss","title":"Adobe Connect stored cross-site scripting in form fields","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.77+00:00","url":"https://junglewise.ai/threats/cve-2026-75697-adobe-connect-is-affected-by-a-stored-cross-site-scripting-xss"}],"high":1,"name":"Adobe Connect For Mobile","rank":5,"slug":"connect-for-mobile","score":41,"vendor":{"name":"Adobe","slug":"adobe"},"critical":6,"max_cvss":9.9,"max_epss":0.0105,"exploited":0,"vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/connect-for-mobile"},{"hub":true,"top":[{"cve":"CVE-2026-75682","cvss":9.9,"epss":0.0054,"slug":"cve-2026-75682-adobe-connect-is-affected-by-an-improper-neutralization-of","title":"Adobe Connect SQL injection leading to arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.26+00:00","url":"https://junglewise.ai/threats/cve-2026-75682-adobe-connect-is-affected-by-an-improper-neutralization-of"},{"cve":"CVE-2026-75698","cvss":9.3,"epss":0.0032,"slug":"cve-2026-75698-adobe-connect-is-affected-by-a-reflected-cross-site-scripting-xss","title":"Adobe Connect reflected Cross-Site Scripting in web page","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.91+00:00","url":"https://junglewise.ai/threats/cve-2026-75698-adobe-connect-is-affected-by-a-reflected-cross-site-scripting-xss"},{"cve":"CVE-2026-75697","cvss":9.3,"epss":0.003,"slug":"cve-2026-75697-adobe-connect-is-affected-by-a-stored-cross-site-scripting-xss","title":"Adobe Connect stored cross-site scripting in form fields","severity":"critical","exploited":false,"published_at":"2026-09-22T19:16:46.77+00:00","url":"https://junglewise.ai/threats/cve-2026-75697-adobe-connect-is-affected-by-a-stored-cross-site-scripting-xss"}],"high":1,"name":"Apple macOS","rank":6,"slug":"macos-tahoe","score":41,"vendor":{"name":"Apple","slug":"apple"},"critical":6,"max_cvss":9.9,"max_epss":0.0105,"exploited":0,"vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-84465","slug":"cve-2026-84465-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad S/MIME signature verification bypass allows sender impersonation","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:58.123+00:00","url":"https://junglewise.ai/threats/cve-2026-84465-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84464","slug":"cve-2026-84464-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad unauthorized data access in External Data Source","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:57.917+00:00","url":"https://junglewise.ai/threats/cve-2026-84464-zammad-is-a-web-based-open-source-helpdesk-customer-support"},{"cve":"CVE-2026-84463","slug":"cve-2026-84463-zammad-is-a-web-based-open-source-helpdesk-customer-support","title":"Zammad HTML injection in Knowledge Base video widget","severity":"info","exploited":false,"published_at":"2026-09-25T19:17:57.763+00:00","url":"https://junglewise.ai/threats/cve-2026-84463-zammad-is-a-web-based-open-source-helpdesk-customer-support"}],"high":0,"name":"Zammad","rank":7,"slug":"zammad","score":30,"vendor":{"name":"Zammad","slug":"zammad"},"critical":0,"max_cvss":null,"max_epss":null,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/zammad"},{"hub":true,"top":[{"cve":"CVE-2026-81549","cvss":9.6,"epss":0.0026,"slug":"cve-2026-81549-ibm-datastage-on-cloud-pak-for-data-5-4-0-0-could-allow-a-remote","title":"IBM DataStage on Cloud Pak for Data SSRF via X-Forwarded-Proto header","severity":"critical","exploited":false,"published_at":"2026-09-24T15:17:39.897+00:00","url":"https://junglewise.ai/threats/cve-2026-81549-ibm-datastage-on-cloud-pak-for-data-5-4-0-0-could-allow-a-remote"},{"cve":"CVE-2026-82093","cvss":8.8,"epss":0.0042,"slug":"cve-2026-82093-ibm-datastage-on-cloud-pak-for-data-5-4-0-0-could-allow-a-remote","title":"IBM DataStage unsafe deserialization remote code execution","severity":"high","exploited":false,"published_at":"2026-09-24T15:17:40.733+00:00","url":"https://junglewise.ai/threats/cve-2026-82093-ibm-datastage-on-cloud-pak-for-data-5-4-0-0-could-allow-a-remote"},{"cve":"CVE-2026-81547","cvss":8.8,"epss":0.0092,"slug":"cve-2026-81547-ibm-datastage-on-cloud-pak-for-data-5-4-0-0-could-allow-a-remote","title":"IBM DataStage on Cloud Pak for Data path traversal command execution","severity":"high","exploited":false,"published_at":"2026-09-24T15:17:39.65+00:00","url":"https://junglewise.ai/threats/cve-2026-81547-ibm-datastage-on-cloud-pak-for-data-5-4-0-0-could-allow-a-remote"}],"high":7,"name":"IBM Datastage On Cloud Pak For Data","rank":8,"slug":"datastage-on-cloud-pak-for-data","score":27,"vendor":{"name":"IBM","slug":"ibm"},"critical":1,"max_cvss":9.6,"max_epss":0.0167,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"hub":false,"top":[{"cve":"CVE-2026-93826","cvss":7.5,"epss":0.0022,"slug":"cve-2026-93826-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel HID subsystem use-after-free in hidpp_connect_event","severity":"high","exploited":false,"published_at":"2026-09-24T17:17:16.297+00:00","url":"https://junglewise.ai/threats/cve-2026-93826-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-98141","slug":"cve-2026-98141-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel NTFS reparse index insertion error handling flaw","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:45.603+00:00","url":"https://junglewise.ai/threats/cve-2026-98141-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-98129","slug":"cve-2026-98129-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel NULL pointer dereference in mpi3mr_sas_port_add","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:44.27+00:00","url":"https://junglewise.ai/threats/cve-2026-98129-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"}],"high":1,"name":"Linux kernel","rank":9,"slug":"x-linux-kernel","score":25,"critical":0,"max_cvss":7.5,"max_epss":0.0022,"exploited":0,"vulnerabilities":23},{"hub":true,"top":[{"cve":"CVE-2026-6928","cvss":9.8,"epss":0.0045,"slug":"cve-2026-6928-ibm-concert-1-0-0-through-3-0-0-references-or-accesses-memory","title":"IBM Concert use-after-free memory corruption","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:02.43+00:00","url":"https://junglewise.ai/threats/cve-2026-6928-ibm-concert-1-0-0-through-3-0-0-references-or-accesses-memory"},{"cve":"CVE-2026-6730","cvss":9.8,"epss":0.0044,"slug":"cve-2026-6730-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-a-buffer-overflow","title":"IBM Concert buffer overflow in local bounds checking","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:02.053+00:00","url":"https://junglewise.ai/threats/cve-2026-6730-ibm-concert-1-0-0-through-3-0-0-is-vulnerable-to-a-buffer-overflow"},{"cve":"CVE-2026-6721","cvss":9.8,"epss":0.0145,"slug":"cve-2026-6721-ibm-concert-1-0-0-through-3-0-0-allows-an-unauthenticated-remote","title":"IBM Concert command injection","severity":"critical","exploited":false,"published_at":"2026-09-23T21:17:01.927+00:00","url":"https://junglewise.ai/threats/cve-2026-6721-ibm-concert-1-0-0-through-3-0-0-allows-an-unauthenticated-remote"}],"high":2,"name":"IBM Concert","rank":10,"slug":"concert","score":25,"vendor":{"name":"IBM","slug":"ibm"},"critical":3,"max_cvss":9.8,"max_epss":0.0145,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/concert"},{"hub":false,"top":[{"cve":"CVE-2026-39353","cvss":9.1,"slug":"cve-2026-39353-invoiceplane-is-a-self-hosted-open-source-application-for","title":"InvoicePlane arbitrary code execution in template inclusion","severity":"critical","exploited":false,"published_at":"2026-09-25T16:17:25.053+00:00","url":"https://junglewise.ai/threats/cve-2026-39353-invoiceplane-is-a-self-hosted-open-source-application-for"},{"cve":"CVE-2026-50547","cvss":7.5,"slug":"cve-2026-50547-invoiceplane-is-a-self-hosted-open-source-application-for","title":"InvoicePlane local file inclusion in invoice XML generation","severity":"high","exploited":false,"published_at":"2026-09-25T16:17:26.3+00:00","url":"https://junglewise.ai/threats/cve-2026-50547-invoiceplane-is-a-self-hosted-open-source-application-for"},{"cve":"CVE-2026-49850","cvss":7.5,"slug":"cve-2026-49850-invoiceplane-is-a-self-hosted-open-source-application-for","title":"InvoicePlane CSRF on invoice deletion endpoints","severity":"high","exploited":false,"published_at":"2026-09-25T16:17:26.14+00:00","url":"https://junglewise.ai/threats/cve-2026-49850-invoiceplane-is-a-self-hosted-open-source-application-for"}],"high":3,"name":"InvoicePlane","rank":11,"slug":"invoiceplane","score":24,"vendor":{"name":"InvoicePlane","slug":"invoiceplane"},"critical":1,"max_cvss":9.1,"max_epss":null,"exploited":0,"vulnerabilities":13},{"hub":true,"top":[{"cve":"CVE-2026-62262","cvss":9.1,"slug":"cve-2026-62262-piwigo-is-a-full-featured-open-source-photo-gallery-application","title":"Piwigo SQL injection in image rating search","severity":"critical","exploited":false,"published_at":"2026-09-25T16:17:26.75+00:00","url":"https://junglewise.ai/threats/cve-2026-62262-piwigo-is-a-full-featured-open-source-photo-gallery-application"},{"cve":"CVE-2026-42322","cvss":9.1,"slug":"cve-2026-42322-piwigo-is-a-full-featured-open-source-photo-gallery-application","title":"Piwigo arbitrary code execution via logo upload extension validation bypass","severity":"critical","exploited":false,"published_at":"2026-09-25T16:17:25.42+00:00","url":"https://junglewise.ai/threats/cve-2026-42322-piwigo-is-a-full-featured-open-source-photo-gallery-application"},{"cve":"CVE-2026-44642","cvss":8.1,"slug":"cve-2026-44642-piwigo-is-a-full-featured-open-source-photo-gallery-application","title":"Piwigo SQL injection in upgrade authentication","severity":"high","exploited":false,"published_at":"2026-09-25T16:17:25.97+00:00","url":"https://junglewise.ai/threats/cve-2026-44642-piwigo-is-a-full-featured-open-source-photo-gallery-application"}],"high":4,"name":"Piwigo","rank":12,"slug":"piwigo","score":24,"vendor":{"name":"Piwigo","slug":"piwigo"},"critical":2,"max_cvss":9.1,"max_epss":null,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/piwigo"},{"hub":false,"top":[{"cve":"CVE-2026-85496","cvss":8.8,"epss":0.0025,"slug":"cve-2026-85496-the-botslab-g980h-dash-camera-firmware-generates-session","title":"Botslab G980H dash camera weak session identifier generation","severity":"high","exploited":false,"published_at":"2026-09-24T20:17:32.89+00:00","url":"https://junglewise.ai/threats/cve-2026-85496-the-botslab-g980h-dash-camera-firmware-generates-session"},{"cve":"CVE-2026-82566","cvss":8.8,"epss":0.0028,"slug":"cve-2026-82566-the-botslab-g980h-dash-camera-firmware-contains-a-session","title":"Botslab G980H session management vulnerability","severity":"high","exploited":false,"published_at":"2026-09-24T20:17:32.503+00:00","url":"https://junglewise.ai/threats/cve-2026-82566-the-botslab-g980h-dash-camera-firmware-contains-a-session"},{"cve":"CVE-2026-81630","cvss":8.1,"epss":0.0019,"slug":"cve-2026-81630-the-botslab-g980h-dash-camera-firmware-does-not-adequately-verify","title":"Botslab G980H firmware signature verification bypass","severity":"high","exploited":false,"published_at":"2026-09-24T21:18:48.737+00:00","url":"https://junglewise.ai/threats/cve-2026-81630-the-botslab-g980h-dash-camera-firmware-does-not-adequately-verify"}],"high":4,"name":"Botslab G980H","rank":13,"slug":"g980h","score":21,"vendor":{"name":"Botslab","slug":"botslab"},"critical":0,"max_cvss":8.8,"max_epss":0.0028,"exploited":0,"vulnerabilities":13},{"hub":true,"top":[{"cve":"CVE-2026-82405","cvss":9.1,"epss":0.0026,"slug":"cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in"},{"cve":"CVE-2026-86064","cvss":8.6,"epss":0.004,"slug":"cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:19.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration"},{"cve":"CVE-2026-86065","cvss":7.5,"epss":0.0035,"slug":"cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/a","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:20.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos"}],"high":6,"name":"github.com/klever-io/klever-go (Go)","rank":14,"slug":"github-com-klever-io-klever-go","score":18,"vendor":{"name":"Go","slug":"go"},"critical":0,"max_cvss":9.1,"max_epss":0.0043,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"hub":true,"top":[{"cve":"CVE-2026-82405","cvss":9.1,"epss":0.0026,"slug":"cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:16.37+00:00","url":"https://junglewise.ai/threats/cve-2026-82405-klever-go-account-takeover-via-authorization-bypass-in"},{"cve":"CVE-2026-86064","cvss":8.6,"epss":0.004,"slug":"cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:19.96+00:00","url":"https://junglewise.ai/threats/cve-2026-86064-klever-go-log-endpoint-unauthenticated-logging-configuration"},{"cve":"CVE-2026-86065","cvss":7.5,"epss":0.0035,"slug":"cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos","title":"Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/a","severity":"high","exploited":false,"published_at":"2026-09-23T20:17:20.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86065-klever-go-unauthenticated-websocket-subscribe-remote-dos"}],"high":6,"name":"Klever Go SDK","rank":15,"slug":"klever-go-sdk","score":18,"vendor":{"name":"Klever","slug":"klever"},"critical":0,"max_cvss":9.1,"max_epss":0.0043,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/klever-go-sdk"},{"hub":false,"top":[{"cve":"CVE-2026-85542","cvss":8.8,"slug":"cve-2026-85542-ibm-guardium-data-protection-12-2-is-affected-by-a-command","title":"IBM Guardium Data Protection command injection in GIM bundle import","severity":"high","exploited":false,"published_at":"2026-09-25T14:17:20.193+00:00","url":"https://junglewise.ai/threats/cve-2026-85542-ibm-guardium-data-protection-12-2-is-affected-by-a-command"},{"cve":"CVE-2026-84893","cvss":7.6,"slug":"cve-2026-84893-ibm-guardium-data-protection-12-2-is-vulnerable-to-sql-injection","title":"IBM Guardium Data Protection SQL injection in PESI service","severity":"high","exploited":false,"published_at":"2026-09-25T14:17:19.913+00:00","url":"https://junglewise.ai/threats/cve-2026-84893-ibm-guardium-data-protection-12-2-is-vulnerable-to-sql-injection"},{"cve":"CVE-2026-84882","cvss":7.5,"slug":"cve-2026-84882-ibm-guardium-data-protection-12-2-is-vulnerable-to-path-traversal","title":"IBM Guardium Data Protection path traversal in Oracle Wallet upload","severity":"high","exploited":false,"published_at":"2026-09-25T15:17:56.273+00:00","url":"https://junglewise.ai/threats/cve-2026-84882-ibm-guardium-data-protection-12-2-is-vulnerable-to-path-traversal"}],"high":6,"name":"IBM Guardium Data Protection","rank":16,"slug":"guardium-data-protection","score":18,"vendor":{"name":"IBM","slug":"ibm"},"critical":0,"max_cvss":8.8,"max_epss":null,"exploited":0,"vulnerabilities":6},{"hub":true,"top":[{"cve":"CVE-2026-85724","cvss":9.6,"epss":0.0026,"slug":"cve-2026-85724-moquette-mqtt-broker-pattern-acl-wildcard-injection-and","title":"Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOpera","severity":"critical","exploited":false,"published_at":"2026-09-23T17:17:17.623+00:00","url":"https://junglewise.ai/threats/cve-2026-85724-moquette-mqtt-broker-pattern-acl-wildcard-injection-and"},{"cve":"CVE-2026-95846","cvss":7.5,"epss":0.0029,"slug":"cve-2026-95846-moquette-is-a-lightweight-java-mqtt-broker-prior-to-0-18-1","title":"Moquette Last-Will authorization bypass","severity":"high","exploited":false,"published_at":"2026-09-23T17:17:21.627+00:00","url":"https://junglewise.ai/threats/cve-2026-95846-moquette-is-a-lightweight-java-mqtt-broker-prior-to-0-18-1"},{"cve":"CVE-2026-95845","cvss":7.5,"epss":0.0029,"slug":"cve-2026-95845-moquette-is-a-lightweight-java-mqtt-broker-prior-to-0-18-1-the","title":"Moquette unbounded message queue denial of service","severity":"high","exploited":false,"published_at":"2026-09-23T17:17:21.47+00:00","url":"https://junglewise.ai/threats/cve-2026-95845-moquette-is-a-lightweight-java-mqtt-broker-prior-to-0-18-1-the"}],"high":4,"name":"Moquette","rank":17,"slug":"moquette","score":18,"vendor":{"name":"Moquette","slug":"moquette"},"critical":1,"max_cvss":9.6,"max_epss":0.0038,"exploited":0,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/moquette"},{"hub":false,"top":[{"cve":"CVE-2026-92609","cvss":9.8,"epss":0.002,"slug":"cve-2026-92609-session-fixation-in-http-management-authentication-allows-remote","title":"Apache Qpid Broker-J session fixation in HTTP management authentication","severity":"critical","exploited":false,"published_at":"2026-09-25T08:16:41.203+00:00","url":"https://junglewise.ai/threats/cve-2026-92609-session-fixation-in-http-management-authentication-allows-remote"},{"cve":"CVE-2026-92560","cvss":7.5,"epss":0.0019,"slug":"cve-2026-92560-a-pre-authentication-attacker-could-leverage-type-size-count","title":"Apache Qpid Broker-J memory exhaustion denial of service","severity":"high","exploited":false,"published_at":"2026-09-25T09:17:06.587+00:00","url":"https://junglewise.ai/threats/cve-2026-92560-a-pre-authentication-attacker-could-leverage-type-size-count"},{"cve":"CVE-2026-92550","cvss":7.5,"epss":0.0019,"slug":"cve-2026-92550-a-pre-authentication-attacker-could-leverage-type-size-count","title":"Apache Qpid Broker-J denial of service via type allocation","severity":"high","exploited":false,"published_at":"2026-09-25T09:17:06.447+00:00","url":"https://junglewise.ai/threats/cve-2026-92550-a-pre-authentication-attacker-could-leverage-type-size-count"}],"high":3,"name":"Apache Qpid Broker-J","rank":18,"slug":"qpid-broker-j","score":17,"vendor":{"name":"Apache","slug":"apache"},"critical":1,"max_cvss":9.8,"max_epss":0.002,"exploited":0,"vulnerabilities":6},{"hub":true,"top":[{"cve":"CVE-2026-75676","cvss":7.8,"epss":0.0019,"slug":"cve-2026-75676-bridge-is-affected-by-a-stack-based-buffer-overflow-vulnerability","title":"Adobe Bridge stack-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-22T19:16:46.037+00:00","url":"https://junglewise.ai/threats/cve-2026-75676-bridge-is-affected-by-a-stack-based-buffer-overflow-vulnerability"},{"cve":"CVE-2026-75665","cvss":7.8,"epss":0.002,"slug":"cve-2026-75665-bridge-is-affected-by-a-heap-based-buffer-overflow-vulnerability","title":"Adobe Bridge heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-22T19:16:45.88+00:00","url":"https://junglewise.ai/threats/cve-2026-75665-bridge-is-affected-by-a-heap-based-buffer-overflow-vulnerability"},{"cve":"CVE-2026-75663","cvss":7.8,"epss":0.0016,"slug":"cve-2026-75663-bridge-is-affected-by-an-out-of-bounds-write-vulnerability-that","title":"Adobe Bridge out-of-bounds write in file handling","severity":"high","exploited":false,"published_at":"2026-09-22T19:16:45.75+00:00","url":"https://junglewise.ai/threats/cve-2026-75663-bridge-is-affected-by-an-out-of-bounds-write-vulnerability-that"}],"high":5,"name":"Adobe Bridge","rank":19,"slug":"bridge","score":16,"vendor":{"name":"Adobe","slug":"adobe"},"critical":0,"max_cvss":7.8,"max_epss":0.002,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/bridge"},{"hub":true,"top":[{"cve":"CVE-2026-94127","cvss":9.8,"epss":0.0223,"slug":"cve-2026-94127-f5-big-ip-apm-heap-based-buffer-overflow","title":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code","severity":"critical","exploited":true,"published_at":"2026-09-22T15:17:24.313+00:00","url":"https://junglewise.ai/threats/cve-2026-94127-f5-big-ip-apm-heap-based-buffer-overflow"}],"high":0,"name":"F5 BIG-IP APM","rank":20,"slug":"big-ip-apm","score":16,"vendor":{"name":"F5","slug":"f5"},"critical":1,"max_cvss":9.8,"max_epss":0.0223,"exploited":1,"vulnerabilities":1,"url":"https://junglewise.ai/threats/technologies/big-ip-apm"},{"hub":false,"top":[{"cve":"CVE-2026-93616","cvss":9.8,"epss":0.1965,"slug":"cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability","title":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Poin","severity":"critical","exploited":true,"published_at":"2026-09-22T13:17:11.963+00:00","url":"https://junglewise.ai/threats/cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability"}],"high":0,"name":"Check Point Log Server","rank":21,"slug":"log-server","score":16,"vendor":{"name":"Check Point","slug":"check-point"},"critical":1,"max_cvss":9.8,"max_epss":0.1965,"exploited":1,"vulnerabilities":1},{"hub":false,"top":[{"cve":"CVE-2026-93616","cvss":9.8,"epss":0.1965,"slug":"cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability","title":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Poin","severity":"critical","exploited":true,"published_at":"2026-09-22T13:17:11.963+00:00","url":"https://junglewise.ai/threats/cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability"}],"high":0,"name":"Check Point Multi-Domain Log Server","rank":22,"slug":"multi-domain-log-server","score":16,"vendor":{"name":"Check Point","slug":"check-point"},"critical":1,"max_cvss":9.8,"max_epss":0.1965,"exploited":1,"vulnerabilities":1},{"hub":false,"top":[{"cve":"CVE-2026-93616","cvss":9.8,"epss":0.1965,"slug":"cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability","title":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Poin","severity":"critical","exploited":true,"published_at":"2026-09-22T13:17:11.963+00:00","url":"https://junglewise.ai/threats/cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability"}],"high":0,"name":"Check Point Multi-Domain Security Management Server","rank":23,"slug":"multi-domain-security-management-server","score":16,"vendor":{"name":"Check Point","slug":"check-point"},"critical":1,"max_cvss":9.8,"max_epss":0.1965,"exploited":1,"vulnerabilities":1},{"hub":false,"top":[{"cve":"CVE-2026-93616","cvss":9.8,"epss":0.1965,"slug":"cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability","title":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Poin","severity":"critical","exploited":true,"published_at":"2026-09-22T13:17:11.963+00:00","url":"https://junglewise.ai/threats/cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability"}],"high":0,"name":"Check Point Security Management Server","rank":24,"slug":"security-management-server","score":16,"vendor":{"name":"Check Point","slug":"check-point"},"critical":1,"max_cvss":9.8,"max_epss":0.1965,"exploited":1,"vulnerabilities":1},{"hub":false,"top":[{"cve":"CVE-2026-93616","cvss":9.8,"epss":0.1965,"slug":"cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability","title":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Poin","severity":"critical","exploited":true,"published_at":"2026-09-22T13:17:11.963+00:00","url":"https://junglewise.ai/threats/cve-2026-93616-check-point-multiple-products-path-traversal-vulnerability"}],"high":0,"name":"Check Point SmartEvent","rank":25,"slug":"smartevent","score":16,"vendor":{"name":"Check Point","slug":"check-point"},"critical":1,"max_cvss":9.8,"max_epss":0.1965,"exploited":1,"vulnerabilities":1}],"last_week_url":"https://junglewise.ai/threats/weekly/2026-09-14","last_month_url":"https://junglewise.ai/threats/monthly/2026-08"}