Weekly report
Most vulnerable technologies: week of 29 June to 5 July 2026 (week 27)
Final report, published . It does not change.
In the week of 29 June to 5 July 2026, Junglewise Threat Intelligence recorded 1,993 new vulnerabilities: 125 critical, 544 high and 4 exploited in the wild. The most vulnerable technology was Google Chrome, with 427 vulnerabilities (0 critical), followed by Go Code.gitea.io/Gitea (38) and Gitea (39).
- New vulnerabilities
- 1,993
- Critical
- 125
- Exploited in the wild
- 4
- Technologies affected
- 931
Ranking
Most affected vendors
- 1.Google438 vulnerabilities, 1 critical, 0 exploited
- 2.Go52 vulnerabilities, 10 critical, 0 exploited
- 3.Microsoft50 vulnerabilities, 4 critical, 0 exploited
- 4.Gitea40 vulnerabilities, 9 critical, 0 exploited
- 5.IBM42 vulnerabilities, 10 critical, 0 exploited
- 6.Npm44 vulnerabilities, 2 critical, 0 exploited
- 7.Pip30 vulnerabilities, 1 critical, 0 exploited
- 8.SourceCodester33 vulnerabilities, 0 critical, 0 exploited
- 9.Ubiquiti20 vulnerabilities, 4 critical, 0 exploited
- 10.Adobe11 vulnerabilities, 8 critical, 1 exploited
Most severe vulnerabilities
- CVE-2026-48282: Adobe ColdFusion path traversal in multiple versionscriticalexploited in the wildCVSS 10EPSS 1.0%
- CVE-2026-56290: Joomlack Page Builder CK unauthenticated arbitrary file uploadcriticalexploited in the wildCVSS 10EPSS 0.4%
- CVE-2026-8452: NetScaler ADC and Gateway memory overflow in Gateway or AAA virtual servercriticalexploited in the wildCVSS 8.8EPSS 1.0%
- CVE-2026-53362: Linux Kernel buffer overflow in IPv6 paged allocationcriticalexploited in the wildCVSS 6.2EPSS 0.7%
- CVE-2026-13768: Gardyn IoT Hub hard-coded privileged key exposurecriticalCVSS 10
- CVE-2026-50746: Ubiquiti UniFi Connect command injection via improper access controlcriticalCVSS 10
- CVE-2026-57624: Creative Themes Blocksy Companion Pro unauthenticated RCEcriticalCVSS 10
- CVE-2026-50160: Hoppscotch mass assignment in onboarding config endpointcriticalCVSS 10
- CVE-2026-56415: StoneFly Storage Concentrator command injection in debug.plcriticalCVSS 10
- CVE-2026-56413: StoneFly Storage Concentrator command injection in ms_service.plcriticalCVSS 10
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-06-29.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 29 June to 5 July 2026 (week 27)", https://junglewise.ai/threats/weekly/2026-06-29, 26 September 2026.