{"schema_version":1,"title":"Most vulnerable technologies: week of 6 to 12 July 2026 (week 28)","summary":"In the week of 6 to 12 July 2026, Junglewise Threat Intelligence recorded 1,592 new vulnerabilities: 93 critical, 461 high and 2 exploited in the wild. The most vulnerable technology was Apache Camel, with 29 vulnerabilities (7 critical), followed by Coollabs Coolify (34) and Coder (21).","url":"https://junglewise.ai/threats/weekly/2026-07-06","json_url":"https://junglewise.ai/threats/weekly/2026-07-06.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/weekly/2026-07-06","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"week","period":{"end":"2026-07-12","start":"2026-07-06"},"totals":{"high":461,"critical":93,"exploited":2,"technologies":948,"vulnerabilities":1592},"notable":[{"cve":"CVE-2026-56291","cvss":10,"epss":0.0028,"slug":"cve-2026-56291-balbooa-forms-for-joomla-unauthenticated-file-upload-rce","title":"Balbooa Forms for Joomla unauthenticated file upload RCE","severity":"critical","exploited":true,"published_at":"2026-07-09T11:16:40.99+00:00","url":"https://junglewise.ai/threats/cve-2026-56291-balbooa-forms-for-joomla-unauthenticated-file-upload-rce"},{"cve":"CVE-2026-59822","cvss":4,"epss":0.0084,"slug":"cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint","title":"BerriAI LiteLLM authentication bypass in MCP endpoint","severity":"critical","exploited":true,"published_at":"2026-07-08T20:16:57.683+00:00","url":"https://junglewise.ai/threats/cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint"},{"cve":"CVE-2026-61447","cvss":10,"slug":"cve-2026-61447-mervinpraison-praisonai-remote-code-execution-in-codeagent","title":"MervinPraison PraisonAI remote code execution in CodeAgent","severity":"critical","exploited":false,"published_at":"2026-07-11T14:16:23.377+00:00","url":"https://junglewise.ai/threats/cve-2026-61447-mervinpraison-praisonai-remote-code-execution-in-codeagent"},{"cve":"CVE-2026-54769","cvss":10,"slug":"cve-2026-54769-langroid-sandbox-escape-and-rce-in-tablechatagent-and-vectorstore","title":"Langroid sandbox escape and RCE in TableChatAgent and VectorStore","severity":"critical","exploited":false,"published_at":"2026-07-10T00:16:33.603+00:00","url":"https://junglewise.ai/threats/cve-2026-54769-langroid-sandbox-escape-and-rce-in-tablechatagent-and-vectorstore"},{"cve":"CVE-2026-59726","cvss":10,"slug":"cve-2026-59726-ruvnet-ruflo-unauthenticated-rce-in-mcp-bridge","title":"ruvnet Ruflo unauthenticated RCE in MCP bridge","severity":"critical","exploited":false,"published_at":"2026-07-09T18:16:57.337+00:00","url":"https://junglewise.ai/threats/cve-2026-59726-ruvnet-ruflo-unauthenticated-rce-in-mcp-bridge"},{"cve":"CVE-2026-54782","cvss":10,"slug":"cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation","title":"CoreWCF authentication bypass in SAML token validation","severity":"critical","exploited":false,"published_at":"2026-07-08T23:16:56.03+00:00","url":"https://junglewise.ai/threats/cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation"},{"cvss":10,"slug":"decolua-9router-multiple-authentication-bypasses-and-sensitive-data-555c07ae","title":"Decolua 9Router multiple authentication bypasses and sensitive data leaks","severity":"critical","exploited":false,"published_at":"2026-07-06T21:22:10+00:00","url":"https://junglewise.ai/threats/decolua-9router-multiple-authentication-bypasses-and-sensitive-data-555c07ae"},{"cve":"CVE-2026-57572","cvss":10,"slug":"cve-2026-57572-unclecode-crawl4ai-remote-code-execution-in-docker-api-server","title":"unclecode Crawl4AI remote code execution in Docker API server","severity":"critical","exploited":false,"published_at":"2026-07-06T21:16:58.047+00:00","url":"https://junglewise.ai/threats/cve-2026-57572-unclecode-crawl4ai-remote-code-execution-in-docker-api-server"},{"cve":"CVE-2026-48316","cvss":10,"slug":"cve-2026-48316-adobe-coldfusion-improper-input-validation-code-execution","title":"Adobe ColdFusion improper input validation code execution","severity":"critical","exploited":false,"published_at":"2026-07-06T17:16:32.01+00:00","url":"https://junglewise.ai/threats/cve-2026-48316-adobe-coldfusion-improper-input-validation-code-execution"},{"cve":"CVE-2026-55500","cvss":9.9,"epss":0.0069,"slug":"cve-2026-55500-decolua-9router-authentication-bypass-in-database-export-and","title":"decolua 9Router authentication bypass in database export and import","severity":"critical","exploited":false,"published_at":"2026-07-10T16:16:33.357+00:00","url":"https://junglewise.ai/threats/cve-2026-55500-decolua-9router-authentication-bypass-in-database-export-and"}],"vendors":[{"hub":true,"high":33,"name":"Pip","rank":1,"slug":"pip","critical":5,"exploited":0,"vulnerabilities":77,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":15,"name":"Apache","rank":2,"slug":"apache","critical":8,"exploited":0,"vulnerabilities":37,"url":"https://junglewise.ai/threats/vendors/apache"},{"hub":true,"high":20,"name":"Npm","rank":3,"slug":"npm","critical":4,"exploited":0,"vulnerabilities":44,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":16,"name":"Coollabs","rank":4,"slug":"coollabs","critical":4,"exploited":0,"vulnerabilities":34,"url":"https://junglewise.ai/threats/vendors/coollabs"},{"hub":true,"high":13,"name":"Go","rank":5,"slug":"go","critical":3,"exploited":0,"vulnerabilities":38,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":10,"name":"Composer","rank":6,"slug":"composer","critical":1,"exploited":0,"vulnerabilities":37,"url":"https://junglewise.ai/threats/vendors/composer"},{"hub":true,"high":5,"name":"Apache Software Foundation","rank":7,"slug":"apache-software-foundation","critical":4,"exploited":0,"vulnerabilities":28,"url":"https://junglewise.ai/threats/vendors/apache-software-foundation"},{"hub":true,"high":11,"name":"Capgo","rank":8,"slug":"capgo","critical":0,"exploited":0,"vulnerabilities":25,"url":"https://junglewise.ai/threats/vendors/capgo"},{"hub":true,"high":10,"name":"Coder","rank":9,"slug":"coder","critical":1,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/vendors/coder"},{"hub":true,"high":7,"name":"Dell","rank":10,"slug":"dell","critical":3,"exploited":0,"vulnerabilities":13,"url":"https://junglewise.ai/threats/vendors/dell"}],"generated_at":"2026-09-26T10:07:00.179841+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-46456","cvss":9.8,"epss":0.0079,"slug":"cve-2026-46456-apache-camel-aws2-sqs-header-injection-in","title":"Apache Camel AWS2-SQS header injection in Sqs2HeaderFilterStrategy","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:36.683+00:00","url":"https://junglewise.ai/threats/cve-2026-46456-apache-camel-aws2-sqs-header-injection-in"},{"cve":"CVE-2026-46455","cvss":9.8,"epss":0.0069,"slug":"cve-2026-46455-apache-camel-insufficient-session-expiration-in-keycloak","title":"Apache Camel insufficient session expiration in Keycloak component","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:36.573+00:00","url":"https://junglewise.ai/threats/cve-2026-46455-apache-camel-insufficient-session-expiration-in-keycloak"},{"cve":"CVE-2026-46454","cvss":9.8,"epss":0.0083,"slug":"cve-2026-46454-apache-camel-improper-input-validation-in-cometd-component","title":"Apache Camel improper input validation in Cometd component","severity":"critical","exploited":false,"published_at":"2026-07-06T09:16:36.457+00:00","url":"https://junglewise.ai/threats/cve-2026-46454-apache-camel-improper-input-validation-in-cometd-component"}],"high":13,"name":"Apache Camel","rank":1,"slug":"camel","score":90,"vendor":{"name":"Apache","slug":"apache"},"critical":7,"max_cvss":9.8,"max_epss":0.0243,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/camel"},{"hub":true,"top":[{"cve":"CVE-2026-34048","cvss":9.9,"slug":"cve-2026-34048-coolify-improper-authorization-in-terminal-websocket-routes","title":"Coolify improper authorization in terminal websocket routes","severity":"critical","exploited":false,"published_at":"2026-07-07T04:17:48.417+00:00","url":"https://junglewise.ai/threats/cve-2026-34048-coolify-improper-authorization-in-terminal-websocket-routes"},{"cve":"CVE-2026-34047","cvss":9.9,"slug":"cve-2026-34047-coolify-incorrect-authorization-in-terminal-websocket-routes","title":"Coolify incorrect authorization in terminal WebSocket routes","severity":"critical","exploited":false,"published_at":"2026-07-07T04:17:48.287+00:00","url":"https://junglewise.ai/threats/cve-2026-34047-coolify-incorrect-authorization-in-terminal-websocket-routes"},{"cve":"CVE-2026-34037","cvss":9.9,"slug":"cve-2026-34037-coolify-cross-tenant-resource-cloning-in-resourceoperations-php","title":"Coolify cross-tenant resource cloning in ResourceOperations.php","severity":"critical","exploited":false,"published_at":"2026-07-07T04:17:48.02+00:00","url":"https://junglewise.ai/threats/cve-2026-34037-coolify-cross-tenant-resource-cloning-in-resourceoperations-php"}],"high":16,"name":"Coollabs Coolify","rank":2,"slug":"coolify","score":86,"vendor":{"name":"Coollabs","slug":"coollabs"},"critical":4,"max_cvss":9.9,"max_epss":null,"exploited":0,"vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/coolify"},{"hub":true,"top":[{"cve":"CVE-2026-46354","cvss":9.1,"slug":"cve-2026-46354-coder-signature-verification-bypass-in-azure-instance-identity","title":"Coder signature verification bypass in Azure instance identity validation","severity":"critical","exploited":false,"published_at":"2026-07-07T22:16:52.467+00:00","url":"https://junglewise.ai/threats/cve-2026-46354-coder-signature-verification-bypass-in-azure-instance-identity"},{"cve":"CVE-2026-55429","cvss":8.7,"slug":"cve-2026-55429-coder-authorization-bypass-via-cross-tenant-workspace-app","title":"Coder authorization bypass via cross-tenant workspace app rebinding","severity":"high","exploited":false,"published_at":"2026-07-08T00:16:33.597+00:00","url":"https://junglewise.ai/threats/cve-2026-55429-coder-authorization-bypass-via-cross-tenant-workspace-app"},{"cve":"CVE-2026-55427","cvss":8.3,"slug":"cve-2026-55427-coder-ssh-configuration-injection-in-coder-config-ssh","title":"Coder SSH configuration injection in coder config-ssh","severity":"high","exploited":false,"published_at":"2026-07-08T00:16:33.323+00:00","url":"https://junglewise.ai/threats/cve-2026-55427-coder-ssh-configuration-injection-in-coder-config-ssh"}],"high":10,"name":"Coder","rank":3,"slug":"coder","score":46,"vendor":{"name":"Coder","slug":"coder"},"critical":1,"max_cvss":9.1,"max_epss":null,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/coder"},{"hub":true,"top":[{"cve":"CVE-2026-56241","cvss":8.3,"slug":"cve-2026-56241-capgo-privilege-escalation-via-stale-rbac-demotion-records","title":"Capgo privilege escalation via stale RBAC demotion records","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:44.73+00:00","url":"https://junglewise.ai/threats/cve-2026-56241-capgo-privilege-escalation-via-stale-rbac-demotion-records"},{"cve":"CVE-2026-56305","cvss":8.3,"slug":"cve-2026-56305-capgo-authentication-bypass-in-password-change-endpoint","title":"Capgo authentication bypass in password change endpoint","severity":"high","exploited":false,"published_at":"2026-07-10T15:16:42.3+00:00","url":"https://junglewise.ai/threats/cve-2026-56305-capgo-authentication-bypass-in-password-change-endpoint"},{"cve":"CVE-2026-56313","cvss":8.1,"slug":"cve-2026-56313-capgo-improper-authorization-in-sso-prelink-endpoint","title":"Capgo improper authorization in SSO prelink endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:45.703+00:00","url":"https://junglewise.ai/threats/cve-2026-56313-capgo-improper-authorization-in-sso-prelink-endpoint"}],"high":10,"name":"Capgo","rank":4,"slug":"capgo","score":44,"vendor":{"name":"Capgo","slug":"capgo"},"critical":0,"max_cvss":8.3,"max_epss":null,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/capgo"},{"hub":true,"top":[{"cve":"CVE-2026-59224","cvss":8,"epss":0.0029,"slug":"cve-2026-59224-open-webui-authentication-bypass-via-terminal-query-injection","title":"Open WebUI authentication bypass via terminal query injection","severity":"high","exploited":false,"published_at":"2026-07-09T17:17:03.77+00:00","url":"https://junglewise.ai/threats/cve-2026-59224-open-webui-authentication-bypass-via-terminal-query-injection"},{"cve":"CVE-2026-59221","cvss":7.7,"epss":0.0048,"slug":"cve-2026-59221-open-webui-path-traversal-bypass-in-terminal-proxy-via-multi","title":"Open WebUI path traversal bypass in terminal proxy via multi-encoding","severity":"high","exploited":false,"published_at":"2026-07-09T18:16:55.613+00:00","url":"https://junglewise.ai/threats/cve-2026-59221-open-webui-path-traversal-bypass-in-terminal-proxy-via-multi"},{"cve":"CVE-2026-59216","cvss":7.7,"epss":0.0045,"slug":"cve-2026-59216-open-webui-code-execution-via-unvalidated-socket-io-session-id","title":"Open WebUI code execution via unvalidated Socket.IO session ID","severity":"high","exploited":false,"published_at":"2026-07-09T17:17:02.467+00:00","url":"https://junglewise.ai/threats/cve-2026-59216-open-webui-code-execution-via-unvalidated-socket-io-session-id"}],"high":8,"name":"Pip Open-Webui","rank":5,"slug":"open-webui","score":38,"vendor":{"name":"Pip","slug":"pip"},"critical":0,"max_cvss":8,"max_epss":0.0057,"exploited":0,"vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"hub":true,"top":[{"cvss":10,"slug":"decolua-9router-multiple-authentication-bypasses-and-sensitive-data-555c07ae","title":"Decolua 9Router multiple authentication bypasses and sensitive data leaks","severity":"critical","exploited":false,"published_at":"2026-07-06T21:22:10+00:00","url":"https://junglewise.ai/threats/decolua-9router-multiple-authentication-bypasses-and-sensitive-data-555c07ae"},{"cve":"CVE-2026-55500","cvss":9.9,"epss":0.0069,"slug":"cve-2026-55500-decolua-9router-authentication-bypass-in-database-export-and","title":"decolua 9Router authentication bypass in database export and import","severity":"critical","exploited":false,"published_at":"2026-07-10T16:16:33.357+00:00","url":"https://junglewise.ai/threats/cve-2026-55500-decolua-9router-authentication-bypass-in-database-export-and"},{"cve":"CVE-2026-59800","cvss":9.8,"epss":0.0204,"slug":"cve-2026-59800-decolua-9router-os-command-injection-in-tailscale-install","title":"decolua 9Router OS command injection in tailscale-install endpoint","severity":"critical","exploited":false,"published_at":"2026-07-07T19:16:55.26+00:00","url":"https://junglewise.ai/threats/cve-2026-59800-decolua-9router-os-command-injection-in-tailscale-install"}],"high":5,"name":"Npm 9router","rank":6,"slug":"9router","score":33,"vendor":{"name":"Npm","slug":"npm"},"critical":3,"max_cvss":10,"max_epss":0.0204,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/9router"},{"hub":true,"top":[{"cvss":8.8,"slug":"n8n-sql-injection-in-mysql-v1-node-executequery-operation-3d263f95","title":"n8n SQL injection in MySQL v1 node executeQuery operation","severity":"high","exploited":false,"published_at":"2026-07-08T15:32:02+00:00","url":"https://junglewise.ai/threats/n8n-sql-injection-in-mysql-v1-node-executequery-operation-3d263f95"},{"cve":"CVE-2026-56776","cvss":7.4,"epss":0.0028,"slug":"cve-2026-56776-n8n-authorization-bypass-in-workflow-test-run-endpoint","title":"n8n authorization bypass in workflow test-run endpoint","severity":"high","exploited":false,"published_at":"2026-07-08T14:17:17.553+00:00","url":"https://junglewise.ai/threats/cve-2026-56776-n8n-authorization-bypass-in-workflow-test-run-endpoint"},{"cve":"CVE-2026-59209","cvss":4,"epss":0.004,"slug":"cve-2026-59209-n8n-credential-leak-in-http-request-node-pagination-expression","title":"n8n credential leak in HTTP Request node pagination expression","severity":"high","exploited":false,"published_at":"2026-07-09T17:17:01.78+00:00","url":"https://junglewise.ai/threats/cve-2026-59209-n8n-credential-leak-in-http-request-node-pagination-expression"}],"high":6,"name":"N8n","rank":7,"slug":"n8n","score":31,"vendor":{"name":"N8n","slug":"n8n"},"critical":0,"max_cvss":8.8,"max_epss":0.0066,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/n8n"},{"hub":true,"top":[{"cve":"CVE-2026-55466","cvss":8.7,"epss":0.0044,"slug":"cve-2026-55466-grokability-snipe-it-stored-xss-in-asset-attachments","title":"Grokability Snipe-IT stored XSS in asset attachments","severity":"high","exploited":false,"published_at":"2026-07-10T20:16:46.97+00:00","url":"https://junglewise.ai/threats/cve-2026-55466-grokability-snipe-it-stored-xss-in-asset-attachments"},{"cve":"CVE-2026-54329","cvss":8.5,"slug":"cve-2026-54329-grokability-snipe-it-mass-assignment-in-accessories-api","title":"Grokability Snipe-IT mass assignment in Accessories API","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:24.44+00:00","url":"https://junglewise.ai/threats/cve-2026-54329-grokability-snipe-it-mass-assignment-in-accessories-api"},{"cve":"CVE-2026-55516","cvss":7.7,"epss":0.0038,"slug":"cve-2026-55516-grokability-snipe-it-authorization-bypass-in-maintenance-api","title":"Grokability Snipe-IT authorization bypass in maintenance API","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:25.71+00:00","url":"https://junglewise.ai/threats/cve-2026-55516-grokability-snipe-it-authorization-bypass-in-maintenance-api"}],"high":5,"name":"Snipeitapp Snipe-It","rank":8,"slug":"snipe-it","score":30,"vendor":{"name":"Snipeitapp","slug":"snipeitapp"},"critical":0,"max_cvss":8.7,"max_epss":0.0059,"exploited":0,"vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/snipe-it"},{"hub":true,"top":[{"cve":"CVE-2026-55466","cvss":8.7,"epss":0.0044,"slug":"cve-2026-55466-grokability-snipe-it-stored-xss-in-asset-attachments","title":"Grokability Snipe-IT stored XSS in asset attachments","severity":"high","exploited":false,"published_at":"2026-07-10T20:16:46.97+00:00","url":"https://junglewise.ai/threats/cve-2026-55466-grokability-snipe-it-stored-xss-in-asset-attachments"},{"cve":"CVE-2026-54329","cvss":8.5,"slug":"cve-2026-54329-grokability-snipe-it-mass-assignment-in-accessories-api","title":"Grokability Snipe-IT mass assignment in Accessories API","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:24.44+00:00","url":"https://junglewise.ai/threats/cve-2026-54329-grokability-snipe-it-mass-assignment-in-accessories-api"},{"cve":"CVE-2026-55516","cvss":7.7,"epss":0.0038,"slug":"cve-2026-55516-grokability-snipe-it-authorization-bypass-in-maintenance-api","title":"Grokability Snipe-IT authorization bypass in maintenance API","severity":"high","exploited":false,"published_at":"2026-07-10T19:17:25.71+00:00","url":"https://junglewise.ai/threats/cve-2026-55516-grokability-snipe-it-authorization-bypass-in-maintenance-api"}],"high":5,"name":"Composer Snipe/Snipe-It","rank":9,"slug":"snipe-snipe-it","score":30,"vendor":{"name":"Composer","slug":"composer"},"critical":0,"max_cvss":8.7,"max_epss":0.0059,"exploited":0,"vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"hub":true,"top":[{"cve":"CVE-2026-57572","cvss":10,"slug":"cve-2026-57572-unclecode-crawl4ai-remote-code-execution-in-docker-api-server","title":"unclecode Crawl4AI remote code execution in Docker API server","severity":"critical","exploited":false,"published_at":"2026-07-06T21:16:58.047+00:00","url":"https://junglewise.ai/threats/cve-2026-57572-unclecode-crawl4ai-remote-code-execution-in-docker-api-server"},{"cve":"CVE-2026-57571","cvss":9.6,"epss":0.0081,"slug":"cve-2026-57571-unclecode-crawl4ai-path-traversal-in-crawler-downloads","title":"UncleCode Crawl4AI Path Traversal in Crawler Downloads","severity":"critical","exploited":false,"published_at":"2026-07-06T21:16:57.907+00:00","url":"https://junglewise.ai/threats/cve-2026-57571-unclecode-crawl4ai-path-traversal-in-crawler-downloads"},{"cve":"CVE-2026-56260","cvss":9.1,"epss":0.0065,"slug":"cve-2026-56260-crawl4ai-arbitrary-file-write-in-docker-api-server-screenshot-and","title":"Crawl4AI arbitrary file write in Docker API server screenshot and pdf endpoints","severity":"critical","exploited":false,"published_at":"2026-07-12T12:16:45.153+00:00","url":"https://junglewise.ai/threats/cve-2026-56260-crawl4ai-arbitrary-file-write-in-docker-api-server-screenshot-and"}],"high":3,"name":"Pip Crawl4ai","rank":10,"slug":"crawl4ai","score":27,"vendor":{"name":"Pip","slug":"pip"},"critical":3,"max_cvss":10,"max_epss":0.0081,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"hub":true,"top":[{"cve":"CVE-2026-54769","cvss":10,"slug":"cve-2026-54769-langroid-sandbox-escape-and-rce-in-tablechatagent-and-vectorstore","title":"Langroid sandbox escape and RCE in TableChatAgent and VectorStore","severity":"critical","exploited":false,"published_at":"2026-07-10T00:16:33.603+00:00","url":"https://junglewise.ai/threats/cve-2026-54769-langroid-sandbox-escape-and-rce-in-tablechatagent-and-vectorstore"},{"cve":"CVE-2026-55615","cvss":4,"epss":0.0046,"slug":"cve-2026-55615-langroid-prompt-injection-in-neo4jchatagent-and-arangochatagent","title":"Langroid prompt injection in Neo4jChatAgent and ArangoChatAgent","severity":"critical","exploited":false,"published_at":"2026-07-10T00:16:33.867+00:00","url":"https://junglewise.ai/threats/cve-2026-55615-langroid-prompt-injection-in-neo4jchatagent-and-arangochatagent"},{"cve":"CVE-2026-54760","cvss":4,"epss":0.0065,"slug":"cve-2026-54760-langroid-sqlchatagent-regex-bypass-in-sql-injection-mitigation","title":"Langroid SQLChatAgent regex bypass in SQL injection mitigation","severity":"critical","exploited":false,"published_at":"2026-07-10T00:16:33.477+00:00","url":"https://junglewise.ai/threats/cve-2026-54760-langroid-sqlchatagent-regex-bypass-in-sql-injection-mitigation"}],"high":3,"name":"Pip Langroid","rank":11,"slug":"langroid","score":27,"vendor":{"name":"Pip","slug":"pip"},"critical":3,"max_cvss":10,"max_epss":0.0065,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/langroid"},{"hub":true,"top":[{"cve":"CVE-2026-15129","cvss":9.8,"slug":"cve-2026-15129-google-chrome-use-after-free-in-views","title":"Google Chrome use after free in Views","severity":"info","exploited":false,"published_at":"2026-07-08T23:16:54.02+00:00","url":"https://junglewise.ai/threats/cve-2026-15129-google-chrome-use-after-free-in-views"},{"cve":"CVE-2026-15128","cvss":8.8,"slug":"cve-2026-15128-google-chrome-uxss-in-forms","title":"Google Chrome UXSS in Forms","severity":"info","exploited":false,"published_at":"2026-07-08T23:16:53.93+00:00","url":"https://junglewise.ai/threats/cve-2026-15128-google-chrome-uxss-in-forms"},{"cve":"CVE-2026-15121","cvss":8.8,"slug":"cve-2026-15121-google-chrome-use-after-free-in-webrtc","title":"Google Chrome use after free in WebRTC","severity":"info","exploited":false,"published_at":"2026-07-08T23:16:53.247+00:00","url":"https://junglewise.ai/threats/cve-2026-15121-google-chrome-use-after-free-in-webrtc"}],"high":0,"name":"Google Chrome","rank":12,"slug":"chrome","score":26,"vendor":{"name":"Google","slug":"google"},"critical":0,"max_cvss":9.8,"max_epss":null,"exploited":0,"vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-53483","cvss":9.8,"slug":"cve-2026-53483-dell-powerprotect-data-domain-improper-authentication","title":"Dell PowerProtect Data Domain improper authentication","severity":"critical","exploited":false,"published_at":"2026-07-07T13:16:31.59+00:00","url":"https://junglewise.ai/threats/cve-2026-53483-dell-powerprotect-data-domain-improper-authentication"},{"cve":"CVE-2026-53481","cvss":9.8,"slug":"cve-2026-53481-dell-powerprotect-data-domain-path-traversal","title":"Dell PowerProtect Data Domain path traversal","severity":"critical","exploited":false,"published_at":"2026-07-07T13:16:31.397+00:00","url":"https://junglewise.ai/threats/cve-2026-53481-dell-powerprotect-data-domain-path-traversal"},{"cve":"CVE-2026-56086","cvss":8.8,"slug":"cve-2026-56086-dell-powerprotect-data-domain-incorrect-authorization","title":"Dell PowerProtect Data Domain incorrect authorization","severity":"high","exploited":false,"published_at":"2026-07-08T14:17:14.98+00:00","url":"https://junglewise.ai/threats/cve-2026-56086-dell-powerprotect-data-domain-incorrect-authorization"}],"high":4,"name":"Dell PowerProtect Data Domain","rank":13,"slug":"powerprotect-data-domain","score":25,"vendor":{"name":"Dell","slug":"dell"},"critical":2,"max_cvss":9.8,"max_epss":null,"exploited":0,"vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/powerprotect-data-domain"},{"hub":true,"top":[{"cve":"CVE-2026-54782","cvss":10,"slug":"cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation","title":"CoreWCF authentication bypass in SAML token validation","severity":"critical","exploited":false,"published_at":"2026-07-08T23:16:56.03+00:00","url":"https://junglewise.ai/threats/cve-2026-54782-corewcf-authentication-bypass-in-saml-token-validation"},{"cve":"CVE-2026-54784","cvss":7.4,"slug":"cve-2026-54784-corewcf-cleartext-proof-key-exposure-in-spnego-negotiation","title":"CoreWCF cleartext proof key exposure in SPNEGO negotiation","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:56.307+00:00","url":"https://junglewise.ai/threats/cve-2026-54784-corewcf-cleartext-proof-key-exposure-in-spnego-negotiation"},{"cve":"CVE-2026-54783","cvss":7.4,"slug":"cve-2026-54783-corewcf-signature-verification-bypass-in-ws-security","title":"CoreWCF signature verification bypass in WS-Security","severity":"high","exploited":false,"published_at":"2026-07-08T23:16:56.173+00:00","url":"https://junglewise.ai/threats/cve-2026-54783-corewcf-signature-verification-bypass-in-ws-security"}],"high":4,"name":"CoreWCF","rank":14,"slug":"corewcf","score":24,"vendor":{"name":"CoreWCF","slug":"corewcf"},"critical":1,"max_cvss":10,"max_epss":null,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/corewcf"},{"hub":true,"top":[{"cve":"CVE-2026-58253","cvss":8.8,"slug":"cve-2026-58253-nats-server-authentication-bypass-in-route-or-leafnode-listeners","title":"NATS Server authentication bypass in route or leafnode listeners","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:54.943+00:00","url":"https://junglewise.ai/threats/cve-2026-58253-nats-server-authentication-bypass-in-route-or-leafnode-listeners"},{"cve":"CVE-2026-58207","cvss":7.7,"slug":"cve-2026-58207-nats-server-integer-overflow-in-connz-pagination-monitoring","title":"NATS Server integer overflow in Connz pagination monitoring requests","severity":"high","exploited":false,"published_at":"2026-07-08T21:16:52.293+00:00","url":"https://junglewise.ai/threats/cve-2026-58207-nats-server-integer-overflow-in-connz-pagination-monitoring"},{"cve":"CVE-2026-58250","cvss":7.5,"slug":"cve-2026-58250-nats-server-null-pointer-dereference-in-leafnode-handshake","title":"NATS Server NULL pointer dereference in leafnode handshake","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:54.483+00:00","url":"https://junglewise.ai/threats/cve-2026-58250-nats-server-null-pointer-dereference-in-leafnode-handshake"}],"high":5,"name":"NATS Server","rank":15,"slug":"nats-server","score":22,"vendor":{"name":"NATS","slug":"nats"},"critical":0,"max_cvss":8.8,"max_epss":null,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/nats-server"},{"hub":true,"top":[{"cve":"CVE-2026-59822","cvss":4,"epss":0.0084,"slug":"cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint","title":"BerriAI LiteLLM authentication bypass in MCP endpoint","severity":"critical","exploited":true,"published_at":"2026-07-08T20:16:57.683+00:00","url":"https://junglewise.ai/threats/cve-2026-59822-berriai-litellm-authentication-bypass-in-mcp-endpoint"},{"cve":"CVE-2026-59821","cvss":4,"epss":0.009,"slug":"cve-2026-59821-berriai-litellm-code-injection-in-custom-code-guardrails","title":"BerriAI LiteLLM code injection in Custom Code Guardrails","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.547+00:00","url":"https://junglewise.ai/threats/cve-2026-59821-berriai-litellm-code-injection-in-custom-code-guardrails"},{"cve":"CVE-2026-59820","cvss":4,"epss":0.0059,"slug":"cve-2026-59820-berriai-litellm-path-traversal-in-skills-archive-extraction","title":"BerriAI LiteLLM path traversal in Skills archive extraction","severity":"medium","exploited":false,"published_at":"2026-07-08T20:16:57.413+00:00","url":"https://junglewise.ai/threats/cve-2026-59820-berriai-litellm-path-traversal-in-skills-archive-extraction"}],"high":0,"name":"Berriai LiteLLM","rank":16,"slug":"litellm","score":19,"vendor":{"name":"Berriai","slug":"berriai"},"critical":1,"max_cvss":4,"max_epss":0.009,"exploited":1,"vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/litellm"},{"hub":true,"top":[{"cve":"CVE-2026-54003","cvss":9.1,"slug":"cve-2026-54003-kirby-cms-authentication-bypass-in-panel-installation-via-header","title":"Kirby CMS authentication bypass in Panel installation via header spoofing","severity":"critical","exploited":false,"published_at":"2026-07-09T19:17:06.12+00:00","url":"https://junglewise.ai/threats/cve-2026-54003-kirby-cms-authentication-bypass-in-panel-installation-via-header"},{"cve":"CVE-2026-54002","cvss":8.5,"slug":"cve-2026-54002-kirby-cms-stored-xss-in-dom-sanitization-component","title":"Kirby CMS stored XSS in Dom sanitization component","severity":"high","exploited":false,"published_at":"2026-07-09T19:17:05.977+00:00","url":"https://junglewise.ai/threats/cve-2026-54002-kirby-cms-stored-xss-in-dom-sanitization-component"},{"cve":"CVE-2026-49276","cvss":7.4,"slug":"cve-2026-49276-kirby-cms-self-xss-in-writer-field","title":"Kirby CMS self-XSS in writer field","severity":"high","exploited":false,"published_at":"2026-07-09T19:17:05.67+00:00","url":"https://junglewise.ai/threats/cve-2026-49276-kirby-cms-self-xss-in-writer-field"}],"high":3,"name":"Kirby","rank":17,"slug":"kirby","score":18,"vendor":{"name":"Kirby","slug":"kirby"},"critical":1,"max_cvss":9.1,"max_epss":null,"exploited":0,"vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/kirby"},{"hub":true,"top":[{"cve":"CVE-2026-42341","cvss":9.2,"slug":"cve-2026-42341-fossbilling-unauthenticated-payment-bypass-in-ipn-callback","title":"FOSSBilling unauthenticated payment bypass in IPN callback","severity":"info","exploited":false,"published_at":"2026-07-06T21:16:55.74+00:00","url":"https://junglewise.ai/threats/cve-2026-42341-fossbilling-unauthenticated-payment-bypass-in-ipn-callback"},{"cve":"CVE-2026-43921","cvss":8.9,"slug":"cve-2026-43921-fossbilling-php-code-injection-in-config-component","title":"FOSSBilling PHP code injection in Config component","severity":"info","exploited":false,"published_at":"2026-07-06T22:16:49.837+00:00","url":"https://junglewise.ai/threats/cve-2026-43921-fossbilling-php-code-injection-in-config-component"},{"cve":"CVE-2026-53643","cvss":8.7,"slug":"cve-2026-53643-fossbilling-authorization-bypass-in-admin-api-endpoints","title":"FOSSBilling authorization bypass in admin API endpoints","severity":"info","exploited":false,"published_at":"2026-07-06T23:16:56.227+00:00","url":"https://junglewise.ai/threats/cve-2026-53643-fossbilling-authorization-bypass-in-admin-api-endpoints"}],"high":0,"name":"FOSSBilling","rank":18,"slug":"fossbilling","score":17,"vendor":{"name":"FOSSBilling","slug":"fossbilling"},"critical":0,"max_cvss":9.2,"max_epss":null,"exploited":0,"vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/fossbilling"},{"hub":true,"top":[{"cve":"CVE-2026-44787","cvss":8.2,"slug":"cve-2026-44787-discourse-privilege-escalation-in-signup-flow","title":"Discourse privilege escalation in signup flow","severity":"high","exploited":false,"published_at":"2026-07-09T22:17:04.607+00:00","url":"https://junglewise.ai/threats/cve-2026-44787-discourse-privilege-escalation-in-signup-flow"},{"cve":"CVE-2026-55420","cvss":7.5,"slug":"cve-2026-55420-discourse-rce-via-pdf-upload-processing","title":"Discourse RCE via PDF upload processing","severity":"high","exploited":false,"published_at":"2026-07-09T18:16:54.44+00:00","url":"https://junglewise.ai/threats/cve-2026-55420-discourse-rce-via-pdf-upload-processing"},{"cve":"CVE-2026-53963","cvss":7.3,"slug":"cve-2026-53963-discourse-stored-xss-in-2fa-delete-confirmation-dialog","title":"Discourse stored XSS in 2FA delete confirmation dialog","severity":"high","exploited":false,"published_at":"2026-07-09T22:17:05.763+00:00","url":"https://junglewise.ai/threats/cve-2026-53963-discourse-stored-xss-in-2fa-delete-confirmation-dialog"}],"high":3,"name":"Discourse","rank":19,"slug":"discourse","score":17,"vendor":{"name":"Discourse","slug":"discourse"},"critical":0,"max_cvss":8.2,"max_epss":null,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/discourse"},{"hub":true,"top":[{"cve":"CVE-2026-56668","cvss":8.1,"epss":0.0041,"slug":"cve-2026-56668-zitadel-privilege-escalation-in-oauth2-token-exchange","title":"ZITADEL privilege escalation in OAuth2 Token Exchange","severity":"high","exploited":false,"published_at":"2026-07-10T18:16:24.413+00:00","url":"https://junglewise.ai/threats/cve-2026-56668-zitadel-privilege-escalation-in-oauth2-token-exchange"},{"cve":"CVE-2026-55672","cvss":7.4,"slug":"cve-2026-55672-zitadel-improper-client-verification-in-oauth2-and-oidc-flows","title":"ZITADEL improper client verification in OAuth2 and OIDC flows","severity":"high","exploited":false,"published_at":"2026-07-10T18:16:23.637+00:00","url":"https://junglewise.ai/threats/cve-2026-55672-zitadel-improper-client-verification-in-oauth2-and-oidc-flows"},{"cve":"CVE-2026-56667","cvss":7.3,"slug":"cve-2026-56667-zitadel-stored-xss-in-oidc-and-saml-login-error-paths","title":"ZITADEL stored XSS in OIDC and SAML login error paths","severity":"high","exploited":false,"published_at":"2026-07-10T18:16:24.283+00:00","url":"https://junglewise.ai/threats/cve-2026-56667-zitadel-stored-xss-in-oidc-and-saml-login-error-paths"}],"high":3,"name":"ZITADEL","rank":20,"slug":"zitadel","score":15,"vendor":{"name":"ZITADEL","slug":"zitadel"},"critical":0,"max_cvss":8.1,"max_epss":0.0041,"exploited":0,"vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/zitadel"},{"hub":true,"top":[{"cve":"CVE-2026-59928","cvss":7.5,"epss":0.0065,"slug":"cve-2026-59928-lepture-mistune-denial-of-service-in-reference-link-parsing","title":"lepture Mistune denial of service in reference-link parsing","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:28.6+00:00","url":"https://junglewise.ai/threats/cve-2026-59928-lepture-mistune-denial-of-service-in-reference-link-parsing"},{"cve":"CVE-2026-59925","cvss":7.5,"epss":0.0064,"slug":"cve-2026-59925-mistune-denial-of-service-via-quadratic-emphasis-parsing","title":"Mistune denial of service via quadratic emphasis parsing","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:28.183+00:00","url":"https://junglewise.ai/threats/cve-2026-59925-mistune-denial-of-service-via-quadratic-emphasis-parsing"},{"cve":"CVE-2026-59922","cvss":7.5,"epss":0.0064,"slug":"cve-2026-59922-lepture-mistune-denial-of-service-in-formatting-plugins","title":"lepture Mistune denial of service in formatting plugins","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:27.77+00:00","url":"https://junglewise.ai/threats/cve-2026-59922-lepture-mistune-denial-of-service-in-formatting-plugins"}],"high":3,"name":"Pip Mistune","rank":21,"slug":"mistune","score":15,"vendor":{"name":"Pip","slug":"pip"},"critical":0,"max_cvss":7.5,"max_epss":0.0065,"exploited":0,"vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/mistune"},{"hub":true,"top":[{"cve":"CVE-2026-44024","cvss":9.8,"slug":"cve-2026-44024-fluent-fluentd-path-traversal-in-tag-placeholder","title":"Fluent Fluentd path traversal in ${tag} placeholder","severity":"critical","exploited":false,"published_at":"2026-07-08T22:17:14.337+00:00","url":"https://junglewise.ai/threats/cve-2026-44024-fluent-fluentd-path-traversal-in-tag-placeholder"},{"cve":"CVE-2026-44160","cvss":7.5,"slug":"cve-2026-44160-fluent-fluentd-denial-of-service-via-decompression-bomb-in-input","title":"Fluent Fluentd denial of service via decompression bomb in input plugins","severity":"high","exploited":false,"published_at":"2026-07-08T22:17:14.6+00:00","url":"https://junglewise.ai/threats/cve-2026-44160-fluent-fluentd-denial-of-service-via-decompression-bomb-in-input"},{"cve":"CVE-2026-44025","cvss":7.5,"slug":"cve-2026-44025-fluent-fluentd-information-disclosure-in-monitor-agent-plugin","title":"Fluent Fluentd information disclosure in Monitor Agent plugin","severity":"high","exploited":false,"published_at":"2026-07-08T22:17:14.473+00:00","url":"https://junglewise.ai/threats/cve-2026-44025-fluent-fluentd-information-disclosure-in-monitor-agent-plugin"}],"high":3,"name":"Rubygems Fluentd","rank":22,"slug":"fluentd","score":15,"vendor":{"name":"Rubygems","slug":"rubygems"},"critical":1,"max_cvss":9.8,"max_epss":null,"exploited":0,"vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/fluentd"},{"hub":true,"top":[{"cve":"CVE-2026-11903","cvss":8,"slug":"cve-2026-11903-progress-moveit-transfer-xss-in-ad-hoc-module","title":"Progress MOVEit Transfer XSS in Ad Hoc module","severity":"high","exploited":false,"published_at":"2026-07-08T15:16:25.47+00:00","url":"https://junglewise.ai/threats/cve-2026-11903-progress-moveit-transfer-xss-in-ad-hoc-module"},{"cve":"CVE-2026-10699","cvss":7.5,"slug":"cve-2026-10699-progress-moveit-transfer-memory-leak-in-custom-reports-modules","title":"Progress MOVEit Transfer memory leak in Custom Reports modules","severity":"high","exploited":false,"published_at":"2026-07-08T15:16:25.173+00:00","url":"https://junglewise.ai/threats/cve-2026-10699-progress-moveit-transfer-memory-leak-in-custom-reports-modules"},{"cve":"CVE-2026-10698","cvss":7.2,"slug":"cve-2026-10698-progress-moveit-transfer-data-query-logic-vulnerability-in-custom","title":"Progress MOVEit Transfer data query logic vulnerability in Custom Reports","severity":"high","exploited":false,"published_at":"2026-07-08T15:16:25.04+00:00","url":"https://junglewise.ai/threats/cve-2026-10698-progress-moveit-transfer-data-query-logic-vulnerability-in-custom"}],"high":3,"name":"Progress MOVEit Transfer","rank":23,"slug":"moveit-transfer","score":14,"vendor":{"name":"Progress","slug":"progress"},"critical":0,"max_cvss":8,"max_epss":null,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/moveit-transfer"},{"hub":true,"top":[{"cve":"CVE-2026-55380","cvss":7.5,"epss":0.0036,"slug":"cve-2026-55380-pillow-heap-allocation-overflow-in-gdimagefile-decompression-bomb","title":"Pillow heap allocation overflow in GdImageFile decompression bomb check","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.703+00:00","url":"https://junglewise.ai/threats/cve-2026-55380-pillow-heap-allocation-overflow-in-gdimagefile-decompression-bomb"},{"cve":"CVE-2026-55379","cvss":7.5,"epss":0.0065,"slug":"cve-2026-55379-pillow-decompression-bomb-protection-bypass-in-bdffontfile","title":"Pillow decompression bomb protection bypass in BdfFontFile","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.577+00:00","url":"https://junglewise.ai/threats/cve-2026-55379-pillow-decompression-bomb-protection-bypass-in-bdffontfile"},{"cve":"CVE-2026-54060","cvss":7.5,"epss":0.0064,"slug":"cve-2026-54060-python-pillow-denial-of-service-via-excessive-memory-allocation","title":"Python Pillow denial of service via excessive memory allocation in FontFile","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.27+00:00","url":"https://junglewise.ai/threats/cve-2026-54060-python-pillow-denial-of-service-via-excessive-memory-allocation"}],"high":4,"name":"Pip Pillow","rank":24,"slug":"pillow","score":13,"vendor":{"name":"Pip","slug":"pip"},"critical":0,"max_cvss":7.5,"max_epss":0.0065,"exploited":0,"vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/pillow"},{"hub":true,"top":[{"cve":"CVE-2026-6896","cvss":8.7,"slug":"cve-2026-6896-gitlab-enterprise-edition-xss-in-vulnerability-evidence-table","title":"GitLab Enterprise Edition XSS in vulnerability evidence table renderer","severity":"high","exploited":false,"published_at":"2026-07-08T21:16:55.097+00:00","url":"https://junglewise.ai/threats/cve-2026-6896-gitlab-enterprise-edition-xss-in-vulnerability-evidence-table"},{"cve":"CVE-2026-13320","cvss":7.3,"slug":"cve-2026-13320-gitlab-ce-ee-html-injection-in-wiki-markup-rendering","title":"GitLab CE/EE HTML injection in wiki markup rendering","severity":"high","exploited":false,"published_at":"2026-07-08T21:16:46.63+00:00","url":"https://junglewise.ai/threats/cve-2026-13320-gitlab-ce-ee-html-injection-in-wiki-markup-rendering"},{"cve":"CVE-2026-11827","cvss":4.9,"slug":"cve-2026-11827-gitlab-gitlab-ee-credential-disclosure-in-repository-mirroring","title":"GitLab GitLab EE credential disclosure in repository mirroring","severity":"medium","exploited":false,"published_at":"2026-07-08T21:16:46.397+00:00","url":"https://junglewise.ai/threats/cve-2026-11827-gitlab-gitlab-ee-credential-disclosure-in-repository-mirroring"}],"high":2,"name":"GitLab Enterprise Edition","rank":25,"slug":"gitlab-ee","score":12,"vendor":{"name":"GitLab","slug":"gitlab"},"critical":0,"max_cvss":8.7,"max_epss":null,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/gitlab-ee"}],"previous":{"key":"2026-06-29","top":"Google Chrome","period":{"end":"2026-07-05","start":"2026-06-29"},"totals":{"high":544,"critical":125,"exploited":4,"technologies":931,"vulnerabilities":1993},"url":"https://junglewise.ai/threats/weekly/2026-06-29"},"next":{"key":"2026-07-13","top":"Microsoft Windows 11","period":{"end":"2026-07-19","start":"2026-07-13"},"totals":{"high":1009,"critical":161,"exploited":14,"technologies":1272,"vulnerabilities":2803},"url":"https://junglewise.ai/threats/weekly/2026-07-13"}}