Junglewise

Weekly report

Most vulnerable technologies: week of 20 to 26 July 2026 (week 30)

Final report, published . It does not change.

In the week of 20 to 26 July 2026, Junglewise Threat Intelligence recorded 3,115 new vulnerabilities: 345 critical, 984 high and 1 exploited in the wild. The most vulnerable technology was Oracle Coherence, with 98 vulnerabilities (62 critical), followed by Linux Kernel (255) and Oracle WebCenter Content (42).

New vulnerabilities
3,115
Critical
345
Exploited in the wild
1
Technologies affected
1,241

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Oracle Coherence
Oracle
986221010
2Linux Kernel
Linux
2550008.2
3Oracle WebCenter Content
Oracle
42636010
4N8n
N8n
5802408.9
5Oracle Service Delivery Platform
Oracle
20163010
6Oracle WebLogic Server
Oracle
23111209.9
7SolarWinds Serv-U
SolarWinds
1514009.1
8Oracle Unified Directory
Oracle
22616010
9Oracle WebCenter Enterprise Capture
Oracle
1411309.9
10Gitea
Gitea
442909.6
11Npm @Budibase/Server
Npm
3031109.8
12Go Code.gitea.io/Gitea
Go
362809.6
13Mozilla Firefox
Mozilla
600008.8
14Oracle Commerce Guided Search
Oracle
1741109.9
15Oracle Access Manager
Oracle
1567010
16Oracle Enterprise Manager Base Platform
Oracle
2321209.8
17Pip Praisonai-Platform
Pip
1641009.8
18Oracle MySQL Cluster
Oracle
430408.4
19Oracle Commerce Experience Manager
Oracle
1531009.9
20Oracle MySQL Server
Oracle
410408.4
21Oracle WebCenter Content: Imaging
Oracle
1411309.8
22Oracle Platform Security for Java
Oracle
1147010
23FFmpeg
Ffmpeg
1601408.8
24Oracle E-Business Suite
Oracle
2101008.8
25Oracle WebCenter Sites
Oracle
104509.9

Most affected vendors

  1. 1.Oracle1,044 vulnerabilities, 200 critical, 0 exploited
  2. 2.Linux255 vulnerabilities, 0 critical, 0 exploited
  3. 3.Npm91 vulnerabilities, 8 critical, 0 exploited
  4. 4.Go76 vulnerabilities, 4 critical, 0 exploited
  5. 5.N8n57 vulnerabilities, 0 critical, 0 exploited
  6. 6.Pip31 vulnerabilities, 6 critical, 0 exploited
  7. 7.SolarWinds15 vulnerabilities, 14 critical, 0 exploited
  8. 8.Microsoft20 vulnerabilities, 11 critical, 0 exploited
  9. 9.Gitea44 vulnerabilities, 2 critical, 0 exploited
  10. 10.Mozilla65 vulnerabilities, 0 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/weekly/2026-07-20.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 20 to 26 July 2026 (week 30)", https://junglewise.ai/threats/weekly/2026-07-20, 26 September 2026.