Junglewise

Weekly report

Most vulnerable technologies: week of 6 to 12 July 2026 (week 28)

Final report, published . It does not change.

In the week of 6 to 12 July 2026, Junglewise Threat Intelligence recorded 1,592 new vulnerabilities: 93 critical, 461 high and 2 exploited in the wild. The most vulnerable technology was Apache Camel, with 29 vulnerabilities (7 critical), followed by Coollabs Coolify (34) and Coder (21).

New vulnerabilities
1,592
Critical
93
Exploited in the wild
2
Technologies affected
948

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Apache Camel
Apache
2971309.8
2Coollabs Coolify
Coollabs
3441609.9
3Coder
Coder
2111009.1
4Capgo
Capgo
2401008.3
5Pip Open-Webui
Pip
220808
6Npm 9router
Npm
835010
7N8n
N8n
190608.8
8Snipeitapp Snipe-It
Snipeitapp
200508.7
9Composer Snipe/Snipe-It
Composer
200508.7
10Pip Crawl4ai
Pip
633010
11Pip Langroid
Pip
633010
12Google Chrome
Google
260009.8
13Dell PowerProtect Data Domain
Dell
72409.8
14CoreWCF
CoreWCF
1114010
15NATS Server
NATS
120508.8
16Berriai LiteLLM
Berriai
41014
17Kirby
Kirby
71309.1
18FOSSBilling
FOSSBilling
170009.2
19Discourse
Discourse
110308.2
20ZITADEL
ZITADEL
90308.1
21Pip Mistune
Pip
90307.5
22Rubygems Fluentd
Rubygems
41309.8
23Progress MOVEit Transfer
Progress
80308
24Pip Pillow
Pip
50407.5
25GitLab Enterprise Edition
GitLab
80208.7

Most affected vendors

  1. 1.Pip77 vulnerabilities, 5 critical, 0 exploited
  2. 2.Apache37 vulnerabilities, 8 critical, 0 exploited
  3. 3.Npm44 vulnerabilities, 4 critical, 0 exploited
  4. 4.Coollabs34 vulnerabilities, 4 critical, 0 exploited
  5. 5.Go38 vulnerabilities, 3 critical, 0 exploited
  6. 6.Composer37 vulnerabilities, 1 critical, 0 exploited
  7. 7.Apache Software Foundation28 vulnerabilities, 4 critical, 0 exploited
  8. 8.Capgo25 vulnerabilities, 0 critical, 0 exploited
  9. 9.Coder21 vulnerabilities, 1 critical, 0 exploited
  10. 10.Dell13 vulnerabilities, 3 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/weekly/2026-07-06.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 6 to 12 July 2026 (week 28)", https://junglewise.ai/threats/weekly/2026-07-06, 26 September 2026.