Weekly report
Most vulnerable technologies: week of 27 July to 2 August 2026 (week 31)
Final report, published . It does not change.
In the week of 27 July to 2 August 2026, Junglewise Threat Intelligence recorded 2,117 new vulnerabilities: 114 critical, 426 high and 7 exploited in the wild. The most vulnerable technology was Google Chrome, with 340 vulnerabilities (0 critical), followed by Apple macOS (159) and Apache Traffic Server (36).
- New vulnerabilities
- 2,117
- Critical
- 114
- Exploited in the wild
- 7
- Technologies affected
- 1,027
Ranking
Most affected vendors
- 1.Google380 vulnerabilities, 1 critical, 0 exploited
- 2.IBM68 vulnerabilities, 13 critical, 0 exploited
- 3.Apple164 vulnerabilities, 0 critical, 0 exploited
- 4.Apache46 vulnerabilities, 6 critical, 0 exploited
- 5.Go41 vulnerabilities, 6 critical, 0 exploited
- 6.Npm45 vulnerabilities, 2 critical, 0 exploited
- 7.Phoenix Contact20 vulnerabilities, 8 critical, 0 exploited
- 8.Red Hat39 vulnerabilities, 0 critical, 0 exploited
- 9.Pip29 vulnerabilities, 2 critical, 0 exploited
- 10.Composer25 vulnerabilities, 4 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-16812: Arista VeloCloud Orchestrator OS command injection in on-prem hostcriticalexploited in the wildCVSS 10
- CVE-2026-59310: VMware vCenter directory traversal in Syslog servercriticalexploited in the wildCVSS 9.8EPSS 2.6%
- CVE-2026-63077: JetBrains TeamCity remote code execution in agent polling protocolcriticalexploited in the wildCVSS 9.8EPSS 0.7%
- CVE-2026-18577: An incomplete patch for allows for authentication bypass and account takeover in N-central Versions through 2026.3.1criticalexploited in the wildCVSS 8.1EPSS 14.6%
- CVE-2026-42016: JFrog Artifactory privilege escalation via improper token scope validationcriticalexploited in the wildCVSS 8.1EPSS 8.6%
- CVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass…criticalexploited in the wildCVSS 7.4EPSS 7.9%
- CVE-2026-20316: Cisco Secure Firewall Management Center static credentials in web interfacecriticalexploited in the wildCVSS 5.3
- CVE-2026-67429: Flytohub Flyto2 Core path traversal in file-writing modulescriticalCVSS 10EPSS 0.8%
- CVE-2026-18452: Rich Source DMS+ hard-coded API keycriticalCVSS 10
- CVE-2026-66803: Microsoft Azure Cosmos DB improper access control remote code executioncriticalCVSS 10
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-07-27.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 27 July to 2 August 2026 (week 31)", https://junglewise.ai/threats/weekly/2026-07-27, 26 September 2026.