Weekly report
Most vulnerable technologies: week of 6 to 12 July 2026 (week 28)
Final report, published . It does not change.
In the week of 6 to 12 July 2026, Junglewise Threat Intelligence recorded 1,592 new vulnerabilities: 93 critical, 461 high and 2 exploited in the wild. The most vulnerable technology was Apache Camel, with 29 vulnerabilities (7 critical), followed by Coollabs Coolify (34) and Coder (21).
- New vulnerabilities
- 1,592
- Critical
- 93
- Exploited in the wild
- 2
- Technologies affected
- 948
Ranking
Most affected vendors
- 1.Pip77 vulnerabilities, 5 critical, 0 exploited
- 2.Apache37 vulnerabilities, 8 critical, 0 exploited
- 3.Npm44 vulnerabilities, 4 critical, 0 exploited
- 4.Coollabs34 vulnerabilities, 4 critical, 0 exploited
- 5.Go38 vulnerabilities, 3 critical, 0 exploited
- 6.Composer37 vulnerabilities, 1 critical, 0 exploited
- 7.Apache Software Foundation28 vulnerabilities, 4 critical, 0 exploited
- 8.Capgo25 vulnerabilities, 0 critical, 0 exploited
- 9.Coder21 vulnerabilities, 1 critical, 0 exploited
- 10.Dell13 vulnerabilities, 3 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-56291: Balbooa Forms for Joomla unauthenticated file upload RCEcriticalexploited in the wildCVSS 10EPSS 0.3%
- CVE-2026-59822: BerriAI LiteLLM authentication bypass in MCP endpointcriticalexploited in the wildCVSS 4EPSS 0.8%
- CVE-2026-61447: MervinPraison PraisonAI remote code execution in CodeAgentcriticalCVSS 10
- CVE-2026-54769: Langroid sandbox escape and RCE in TableChatAgent and VectorStorecriticalCVSS 10
- CVE-2026-59726: ruvnet Ruflo unauthenticated RCE in MCP bridgecriticalCVSS 10
- CVE-2026-54782: CoreWCF authentication bypass in SAML token validationcriticalCVSS 10
- Decolua 9Router multiple authentication bypasses and sensitive data leakscriticalCVSS 10
- CVE-2026-57572: unclecode Crawl4AI remote code execution in Docker API servercriticalCVSS 10
- CVE-2026-48316: Adobe ColdFusion improper input validation code executioncriticalCVSS 10
- CVE-2026-55500: decolua 9Router authentication bypass in database export and importcriticalCVSS 9.9EPSS 0.7%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-07-06.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 6 to 12 July 2026 (week 28)", https://junglewise.ai/threats/weekly/2026-07-06, 26 September 2026.