Weekly report
Most vulnerable technologies: week of 20 to 26 July 2026 (week 30)
Final report, published . It does not change.
In the week of 20 to 26 July 2026, Junglewise Threat Intelligence recorded 3,115 new vulnerabilities: 345 critical, 984 high and 1 exploited in the wild. The most vulnerable technology was Oracle Coherence, with 98 vulnerabilities (62 critical), followed by Linux Kernel (255) and Oracle WebCenter Content (42).
- New vulnerabilities
- 3,115
- Critical
- 345
- Exploited in the wild
- 1
- Technologies affected
- 1,241
Ranking
Most affected vendors
- 1.Oracle1,044 vulnerabilities, 200 critical, 0 exploited
- 2.Linux255 vulnerabilities, 0 critical, 0 exploited
- 3.Npm91 vulnerabilities, 8 critical, 0 exploited
- 4.Go76 vulnerabilities, 4 critical, 0 exploited
- 5.N8n57 vulnerabilities, 0 critical, 0 exploited
- 6.Pip31 vulnerabilities, 6 critical, 0 exploited
- 7.SolarWinds15 vulnerabilities, 14 critical, 0 exploited
- 8.Microsoft20 vulnerabilities, 11 critical, 0 exploited
- 9.Gitea44 vulnerabilities, 2 critical, 0 exploited
- 10.Mozilla65 vulnerabilities, 0 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-16232: Check Point SmartConsole authentication bypass in login processcriticalexploited in the wildCVSS 9.8
- CVE-2026-47668: DbGate remote code execution in JSON script runnercriticalCVSS 10EPSS 3.9%
- CVE-2026-46412: BeProduct @beproduct/nestjs-auth malicious code injection via npm supply chain attackcriticalCVSS 10EPSS 0.8%
- CVE-2026-66012: SiYuan missing authorization in MCP kernel endpointcriticalCVSS 10
- Pheditor authentication bypass in forced password-change flowcriticalCVSS 10
- Microsoft Prompty SSTI to RCE in Nunjucks RenderercriticalCVSS 10
- CVE-2026-58630: Microsoft Azure App Service privilege escalationcriticalCVSS 10
- CVE-2026-57106: Microsoft Purview Data Governance SSRF in Data QualitycriticalCVSS 10
- CVE-2026-56163: Microsoft Azure Kubernetes Service missing authentication privilege escalationcriticalCVSS 10
- CVE-2026-62825: Microsoft Azure Key Vault improper authentication privilege escalationcriticalCVSS 10
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-07-20.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 20 to 26 July 2026 (week 30)", https://junglewise.ai/threats/weekly/2026-07-20, 26 September 2026.