Junglewise

Weekly report

Most vulnerable technologies: week of 27 July to 2 August 2026 (week 31)

Final report, published . It does not change.

In the week of 27 July to 2 August 2026, Junglewise Threat Intelligence recorded 2,117 new vulnerabilities: 114 critical, 426 high and 7 exploited in the wild. The most vulnerable technology was Google Chrome, with 340 vulnerabilities (0 critical), followed by Apple macOS (159) and Apache Traffic Server (36).

New vulnerabilities
2,117
Critical
114
Exploited in the wild
7
Technologies affected
1,027

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Google Chrome
Google
34000010
2Apple macOS
Apple
1590005.5
3Apache Traffic Server
Apache
36621010
4Apple iPadOS
Apple
840005.5
5Phoenix Contact CHARX SEC-3000
Phoenix Contact
198809.8
6Phoenix Contact CHARX SEC-3050
Phoenix Contact
198809.8
7Phoenix Contact CHARX SEC-3100
Phoenix Contact
198809.8
8Phoenix Contact CHARX SEC-3150
Phoenix Contact
198809.8
9Apple tvOS
Apple
660005.5
10Apple visionOS
Apple
650005.5
11Apple watchOS
Apple
620005.5
12IBM WebSphere Application Server
IBM
1541009.8
13Axios
Axios
2801207.5
14Three Learning Koollab LMS
Three Learning
166109.9
15IBM WebSphere Application Server Liberty
IBM
1411209.4
16Koxudaxi Datamodel-Code-Generator
Koxudaxi
1201108.8
17Google Chrome for iOS
Google
330008.8
18Gitpython Project Gitpython
Gitpython Project
92709.8
19VMware Cloud Foundation
VMware
53119.8
20N-able N-central
N-able
22028.1
21Red Hat Enterprise Linux 10
Red Hat
130908.8
22IBM Langflow
IBM
83309.9
23VMware vSphere Foundation
VMware
43019.8
24ArcadeData ArcadeDB
ArcadeData
82509.8
25Linux Kernel
Linux
270006.2

Most affected vendors

  1. 1.Google380 vulnerabilities, 1 critical, 0 exploited
  2. 2.IBM68 vulnerabilities, 13 critical, 0 exploited
  3. 3.Apple164 vulnerabilities, 0 critical, 0 exploited
  4. 4.Apache46 vulnerabilities, 6 critical, 0 exploited
  5. 5.Go41 vulnerabilities, 6 critical, 0 exploited
  6. 6.Npm45 vulnerabilities, 2 critical, 0 exploited
  7. 7.Phoenix Contact20 vulnerabilities, 8 critical, 0 exploited
  8. 8.Red Hat39 vulnerabilities, 0 critical, 0 exploited
  9. 9.Pip29 vulnerabilities, 2 critical, 0 exploited
  10. 10.Composer25 vulnerabilities, 4 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/weekly/2026-07-27.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 27 July to 2 August 2026 (week 31)", https://junglewise.ai/threats/weekly/2026-07-27, 26 September 2026.