Weekly report
Most vulnerable technologies: week of 3 to 9 August 2026 (week 32)
Final report, published . It does not change.
In the week of 3 to 9 August 2026, Junglewise Threat Intelligence recorded 670 new vulnerabilities: 90 critical, 238 high and 2 exploited in the wild. The most vulnerable technology was Npm Flowise, with 29 vulnerabilities (11 critical), followed by D-Link DWR-M961 (15) and Npm Flowise-Components (12).
- New vulnerabilities
- 670
- Critical
- 90
- Exploited in the wild
- 2
- Technologies affected
- 981
Ranking
Most affected vendors
- 1.Npm57 vulnerabilities, 14 critical, 0 exploited
- 2.D-Link15 vulnerabilities, 15 critical, 0 exploited
- 3.Pip35 vulnerabilities, 0 critical, 0 exploited
- 4.Go24 vulnerabilities, 3 critical, 0 exploited
- 5.Linux19 vulnerabilities, 2 critical, 0 exploited
- 6.Progress10 vulnerabilities, 7 critical, 0 exploited
- 7.Cisco15 vulnerabilities, 2 critical, 0 exploited
- 8.Nvidia16 vulnerabilities, 1 critical, 0 exploited
- 9.OpenReception15 vulnerabilities, 4 critical, 0 exploited
- 10.Bouncy Castle13 vulnerabilities, 2 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-5430: The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported…criticalexploited in the wildCVSS 10EPSS 0.6%
- CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS…criticalexploited in the wildCVSS 9.8EPSS 1.2%
- CVE-2026-70478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…criticalCVSS 10EPSS 0.6%
- SiYuan SQL injection in fullTextSearchAssetContent endpointcriticalCVSS 10
- SiYuan searchEmbedBlock SQL injectioncriticalCVSS 10
- CVE-2026-7329: Progress MarkLogic Server privilege escalation in query interfacescriticalCVSS 9.9EPSS 0.6%
- CVE-2026-9193: Progress MarkLogic Server privilege escalation in Hadoop integrationcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-8709: Progress MarkLogic Server REST API privilege escalation in document patchcriticalCVSS 9.9EPSS 0.5%
- CVE-2026-48086: OpenReception privilege escalation in role-update handlercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-18616: GL-iNet GL-MT3000 command injection in wg-servercriticalCVSS 9.8EPSS 3.6%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-08-03.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 3 to 9 August 2026 (week 32)", https://junglewise.ai/threats/weekly/2026-08-03, 26 September 2026.