Junglewise

Weekly report

Most vulnerable technologies: week of 3 to 9 August 2026 (week 32)

Final report, published . It does not change.

In the week of 3 to 9 August 2026, Junglewise Threat Intelligence recorded 670 new vulnerabilities: 90 critical, 238 high and 2 exploited in the wild. The most vulnerable technology was Npm Flowise, with 29 vulnerabilities (11 critical), followed by D-Link DWR-M961 (15) and Npm Flowise-Components (12).

New vulnerabilities
670
Critical
90
Exploited in the wild
2
Technologies affected
981

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Npm Flowise
Npm
291114010
2D-Link DWR-M961
D-Link
1515009.8
3Npm Flowise-Components
Npm
129209.8
4Linux Kernel
Linux
1921109.8
5Progress Marklogic Server
Progress
107309.9
6Nvidia Dynamo
Nvidia
1511009.8
7OpenReception Appointment-Booking-Software
OpenReception
143309.9
8Bouncy Castle for Java
Bouncy Castle
111809.1
9Pip Open-Webui
Pip
170608.7
10Open62541 Project Open62541
Open62541 Project
100807.5
11SiYuan
SiYuan
824010
12OpenSIPS
OpenSIPS
83109.8
13H3C NX15
H3C
80807.3
14Wso2 API Manager
Wso2
420110
15MSI Radix AXE6600
MSI
44009.8
16Bouncycastle Bouncy Castle For Java Lts
Bouncycastle
81509.1
17Nvidia Dynamo for Linux
Nvidia
71509.8
18Wso2 API Control Plane
Wso2
220110
19Wso2 Traffic Manager
Wso2
220110
20Wso2 Universal Gateway
Wso2
220110
21Gitpython Project Gitpython
Gitpython Project
90608.8
22Cisco IOS XE
Cisco
61509.8
23Microsoft Edge Chromium
Microsoft
110408.1
24Microsoft Edge
Microsoft
110408.1
25Wso2 Enterprise Integrator
Wso2
310110

Most affected vendors

  1. 1.Npm57 vulnerabilities, 14 critical, 0 exploited
  2. 2.D-Link15 vulnerabilities, 15 critical, 0 exploited
  3. 3.Pip35 vulnerabilities, 0 critical, 0 exploited
  4. 4.Go24 vulnerabilities, 3 critical, 0 exploited
  5. 5.Linux19 vulnerabilities, 2 critical, 0 exploited
  6. 6.Progress10 vulnerabilities, 7 critical, 0 exploited
  7. 7.Cisco15 vulnerabilities, 2 critical, 0 exploited
  8. 8.Nvidia16 vulnerabilities, 1 critical, 0 exploited
  9. 9.OpenReception15 vulnerabilities, 4 critical, 0 exploited
  10. 10.Bouncy Castle13 vulnerabilities, 2 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/weekly/2026-08-03.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 3 to 9 August 2026 (week 32)", https://junglewise.ai/threats/weekly/2026-08-03, 26 September 2026.