Weekly reports
Weekly vulnerability reports
Updated . Rebuilt every hour.
The most vulnerable technologies of each week, Monday to Sunday (UTC), ranked by Junglewise Threat Intelligence. The latest report covers the week of 14 to 20 September 2026: 4,840 vulnerabilities, led by Linux Kernel.
Every week
- Week of 14 to 20 September 2026 (week 38)4,840 vulnerabilities, 468 critical, 4 exploited in the wild. Most vulnerable: Linux Kernel
- Week of 7 to 13 September 2026 (week 37)3,792 vulnerabilities, 319 critical, 9 exploited in the wild. Most vulnerable: Linux Kernel
- Week of 31 August to 6 September 2026 (week 36)2,379 vulnerabilities, 294 critical, 7 exploited in the wild. Most vulnerable: Linux Kernel
- Week of 24 to 30 August 2026 (week 35)2,819 vulnerabilities, 331 critical, 10 exploited in the wild. Most vulnerable: Google Chrome
- Week of 17 to 23 August 2026 (week 34)2,072 vulnerabilities, 270 critical, 4 exploited in the wild. Most vulnerable: Linux Kernel
- Week of 10 to 16 August 2026 (week 33)1,900 vulnerabilities, 222 critical, 6 exploited in the wild. Most vulnerable: Linux Kernel
- Week of 3 to 9 August 2026 (week 32)670 vulnerabilities, 90 critical, 2 exploited in the wild. Most vulnerable: Npm Flowise
- Week of 27 July to 2 August 2026 (week 31)2,117 vulnerabilities, 114 critical, 7 exploited in the wild. Most vulnerable: Google Chrome
- Week of 20 to 26 July 2026 (week 30)3,115 vulnerabilities, 345 critical, 1 exploited in the wild. Most vulnerable: Oracle Coherence
- Week of 13 to 19 July 2026 (week 29)2,803 vulnerabilities, 161 critical, 14 exploited in the wild. Most vulnerable: Microsoft Windows 11
- Week of 6 to 12 July 2026 (week 28)1,592 vulnerabilities, 93 critical, 2 exploited in the wild. Most vulnerable: Apache Camel
- Week of 29 June to 5 July 2026 (week 27)1,993 vulnerabilities, 125 critical, 4 exploited in the wild. Most vulnerable: Google Chrome
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.