{"schema_version":1,"title":"Most vulnerable technologies: week of 3 to 9 August 2026 (week 32)","summary":"In the week of 3 to 9 August 2026, Junglewise Threat Intelligence recorded 670 new vulnerabilities: 90 critical, 238 high and 2 exploited in the wild. The most vulnerable technology was Npm Flowise, with 29 vulnerabilities (11 critical), followed by D-Link DWR-M961 (15) and Npm Flowise-Components (12).","url":"https://junglewise.ai/threats/weekly/2026-08-03","json_url":"https://junglewise.ai/threats/weekly/2026-08-03.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/weekly/2026-08-03","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"week","period":{"end":"2026-08-09","start":"2026-08-03"},"totals":{"high":238,"critical":90,"exploited":2,"technologies":981,"vulnerabilities":670},"notable":[{"cve":"CVE-2026-5430","cvss":10,"epss":0.0058,"slug":"cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability","title":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an a","severity":"critical","exploited":true,"published_at":"2026-08-06T08:16:33.24+00:00","url":"https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability"},{"cve":"CVE-2026-65400","cvss":9.8,"epss":0.0122,"slug":"cve-2026-65400-apple-macos-screen-sharing-authentication-bypass","title":"An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, mac","severity":"critical","exploited":true,"published_at":"2026-08-06T22:18:14.533+00:00","url":"https://junglewise.ai/threats/cve-2026-65400-apple-macos-screen-sharing-authentication-bypass"},{"cve":"CVE-2026-70478","cvss":10,"epss":0.0062,"slug":"cve-2026-70478-flowise-unauthenticated-oauth2-token-refresh-in-credential","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:54.61+00:00","url":"https://junglewise.ai/threats/cve-2026-70478-flowise-unauthenticated-oauth2-token-refresh-in-credential"},{"cvss":10,"slug":"siyuan-sql-injection-in-fulltextsearchassetcontent-endpoint-77bd29ce","title":"SiYuan SQL injection in fullTextSearchAssetContent endpoint","severity":"critical","exploited":false,"published_at":"2026-08-03T15:32:48+00:00","url":"https://junglewise.ai/threats/siyuan-sql-injection-in-fulltextsearchassetcontent-endpoint-77bd29ce"},{"cvss":10,"slug":"siyuan-searchembedblock-sql-injection-1301810a","title":"SiYuan searchEmbedBlock SQL injection","severity":"critical","exploited":false,"published_at":"2026-08-03T15:32:48+00:00","url":"https://junglewise.ai/threats/siyuan-searchembedblock-sql-injection-1301810a"},{"cve":"CVE-2026-7329","cvss":9.9,"epss":0.0057,"slug":"cve-2026-7329-progress-marklogic-server-privilege-escalation-in-query-interfaces","title":"Progress MarkLogic Server privilege escalation in query interfaces","severity":"critical","exploited":false,"published_at":"2026-08-05T16:17:09.2+00:00","url":"https://junglewise.ai/threats/cve-2026-7329-progress-marklogic-server-privilege-escalation-in-query-interfaces"},{"cve":"CVE-2026-9193","cvss":9.9,"epss":0.0046,"slug":"cve-2026-9193-progress-marklogic-server-privilege-escalation-in-hadoop","title":"Progress MarkLogic Server privilege escalation in Hadoop integration","severity":"critical","exploited":false,"published_at":"2026-08-05T16:17:10.183+00:00","url":"https://junglewise.ai/threats/cve-2026-9193-progress-marklogic-server-privilege-escalation-in-hadoop"},{"cve":"CVE-2026-8709","cvss":9.9,"epss":0.0046,"slug":"cve-2026-8709-progress-marklogic-server-rest-api-privilege-escalation-in","title":"Progress MarkLogic Server REST API privilege escalation in document patch","severity":"critical","exploited":false,"published_at":"2026-08-05T16:17:09.82+00:00","url":"https://junglewise.ai/threats/cve-2026-8709-progress-marklogic-server-rest-api-privilege-escalation-in"},{"cve":"CVE-2026-48086","cvss":9.9,"epss":0.0044,"slug":"cve-2026-48086-openreception-privilege-escalation-in-role-update-handler","title":"OpenReception privilege escalation in role-update handler","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.593+00:00","url":"https://junglewise.ai/threats/cve-2026-48086-openreception-privilege-escalation-in-role-update-handler"},{"cve":"CVE-2026-18616","cvss":9.8,"epss":0.0362,"slug":"cve-2026-18616-gl-inet-gl-mt3000-command-injection-in-wg-server","title":"GL-iNet GL-MT3000 command injection in wg-server","severity":"critical","exploited":false,"published_at":"2026-08-03T19:16:45.557+00:00","url":"https://junglewise.ai/threats/cve-2026-18616-gl-inet-gl-mt3000-command-injection-in-wg-server"}],"vendors":[{"hub":true,"high":18,"name":"Npm","rank":1,"slug":"npm","critical":14,"exploited":0,"vulnerabilities":57,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":0,"name":"D-Link","rank":2,"slug":"d-link","critical":15,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/vendors/d-link"},{"hub":true,"high":15,"name":"Pip","rank":3,"slug":"pip","critical":0,"exploited":0,"vulnerabilities":35,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":8,"name":"Go","rank":4,"slug":"go","critical":3,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":11,"name":"Linux","rank":5,"slug":"linux","critical":2,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":3,"name":"Progress","rank":6,"slug":"progress","critical":7,"exploited":0,"vulnerabilities":10,"url":"https://junglewise.ai/threats/vendors/progress"},{"hub":true,"high":9,"name":"Cisco","rank":7,"slug":"cisco","critical":2,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/vendors/cisco"},{"hub":true,"high":10,"name":"Nvidia","rank":8,"slug":"nvidia","critical":1,"exploited":0,"vulnerabilities":16,"url":"https://junglewise.ai/threats/vendors/nvidia"},{"hub":true,"high":3,"name":"OpenReception","rank":9,"slug":"openreception","critical":4,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/vendors/openreception"},{"hub":true,"high":9,"name":"Bouncy Castle","rank":10,"slug":"bouncy-castle","critical":2,"exploited":0,"vulnerabilities":13,"url":"https://junglewise.ai/threats/vendors/bouncy-castle"}],"generated_at":"2026-09-26T09:24:00.138874+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-70478","cvss":10,"epss":0.0062,"slug":"cve-2026-70478-flowise-unauthenticated-oauth2-token-refresh-in-credential","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:54.61+00:00","url":"https://junglewise.ai/threats/cve-2026-70478-flowise-unauthenticated-oauth2-token-refresh-in-credential"},{"cve":"CVE-2026-70477","cvss":9.8,"epss":0.0081,"slug":"cve-2026-70477-flowise-rce-via-csv-agent-prompt-injection","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatfl","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:54.473+00:00","url":"https://junglewise.ai/threats/cve-2026-70477-flowise-rce-via-csv-agent-prompt-injection"},{"cve":"CVE-2026-70470","cvss":9.8,"epss":0.0097,"slug":"cve-2026-70470-flowise-pyodide-validator-unicode-homoglyph-bypass-in-csv-and","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFr","severity":"critical","exploited":false,"published_at":"2026-08-04T18:16:57.93+00:00","url":"https://junglewise.ai/threats/cve-2026-70470-flowise-pyodide-validator-unicode-homoglyph-bypass-in-csv-and"}],"high":14,"name":"Npm Flowise","rank":1,"slug":"flowise","score":112,"vendor":{"name":"Npm","slug":"npm"},"critical":11,"max_cvss":10,"max_epss":0.0274,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/flowise"},{"hub":true,"top":[{"cve":"CVE-2026-71958","cvss":9.8,"epss":0.0107,"slug":"cve-2026-71958-d-link-dwr-m961-buffer-overflow-in-quicksetup-cgi","title":"D-Link DWR-M961 buffer overflow in quicksetup.cgi","severity":"critical","exploited":false,"published_at":"2026-08-08T18:16:56.783+00:00","url":"https://junglewise.ai/threats/cve-2026-71958-d-link-dwr-m961-buffer-overflow-in-quicksetup-cgi"},{"cve":"CVE-2026-71957","cvss":9.8,"epss":0.0107,"slug":"cve-2026-71957-d-link-dwr-m961-buffer-overflow-in-app-cgi","title":"D-Link DWR-M961 buffer overflow in app.cgi","severity":"critical","exploited":false,"published_at":"2026-08-08T18:16:56.647+00:00","url":"https://junglewise.ai/threats/cve-2026-71957-d-link-dwr-m961-buffer-overflow-in-app-cgi"},{"cve":"CVE-2026-71956","cvss":9.8,"epss":0.0317,"slug":"cve-2026-71956-d-link-dwr-m961-command-injection-in-web-management-cgi","title":"D-Link DWR-M961 command injection in web-management CGI","severity":"critical","exploited":false,"published_at":"2026-08-08T18:16:56.503+00:00","url":"https://junglewise.ai/threats/cve-2026-71956-d-link-dwr-m961-command-injection-in-web-management-cgi"}],"high":0,"name":"D-Link DWR-M961","rank":2,"slug":"dwr-m961","score":90,"vendor":{"name":"D-Link","slug":"d-link"},"critical":15,"max_cvss":9.8,"max_epss":0.0317,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/dwr-m961"},{"hub":true,"top":[{"cve":"CVE-2026-70477","cvss":9.8,"epss":0.0081,"slug":"cve-2026-70477-flowise-rce-via-csv-agent-prompt-injection","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatfl","severity":"critical","exploited":false,"published_at":"2026-08-04T20:16:54.473+00:00","url":"https://junglewise.ai/threats/cve-2026-70477-flowise-rce-via-csv-agent-prompt-injection"},{"cve":"CVE-2026-70470","cvss":9.8,"epss":0.0097,"slug":"cve-2026-70470-flowise-pyodide-validator-unicode-homoglyph-bypass-in-csv-and","title":"Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFr","severity":"critical","exploited":false,"published_at":"2026-08-04T18:16:57.93+00:00","url":"https://junglewise.ai/threats/cve-2026-70470-flowise-pyodide-validator-unicode-homoglyph-bypass-in-csv-and"},{"cve":"CVE-2026-69264","cvss":9.8,"epss":0.0111,"slug":"cve-2026-69264-flowise-flowise-rce-via-python-injection-in-csvagent","title":"Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code temp","severity":"critical","exploited":false,"published_at":"2026-08-04T18:16:57.027+00:00","url":"https://junglewise.ai/threats/cve-2026-69264-flowise-flowise-rce-via-python-injection-in-csvagent"}],"high":2,"name":"Npm Flowise-Components","rank":3,"slug":"flowise-components","score":61,"vendor":{"name":"Npm","slug":"npm"},"critical":9,"max_cvss":9.8,"max_epss":0.0274,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"hub":true,"top":[{"cve":"CVE-2026-68082","cvss":9.8,"epss":0.0076,"slug":"cve-2026-68082-linux-kernel-libceph-out-of-bounds-read-in-decode-lockers","title":"Linux kernel libceph out-of-bounds read in decode_lockers","severity":"critical","exploited":false,"published_at":"2026-08-08T10:16:55.377+00:00","url":"https://junglewise.ai/threats/cve-2026-68082-linux-kernel-libceph-out-of-bounds-read-in-decode-lockers"},{"cve":"CVE-2026-24254","cvss":9.8,"epss":0.0089,"slug":"cve-2026-24254-nvidia-dynamo-for-linux-out-of-bounds-write-in-multimodal-serving","title":"NVIDIA Dynamo for Linux out-of-bounds write in multimodal serving topology","severity":"critical","exploited":false,"published_at":"2026-08-04T18:16:49.937+00:00","url":"https://junglewise.ai/threats/cve-2026-24254-nvidia-dynamo-for-linux-out-of-bounds-write-in-multimodal-serving"},{"cve":"CVE-2026-64561","cvss":8.8,"slug":"cve-2026-64561-linux-kvm-x86-shadow-mmu-privilege-escalation","title":"Linux KVM x86 shadow MMU privilege escalation","severity":"high","exploited":false,"published_at":"2026-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-64561-linux-kvm-x86-shadow-mmu-privilege-escalation"}],"high":11,"name":"Linux Kernel","rank":4,"slug":"kernel","score":51,"vendor":{"name":"Linux","slug":"linux"},"critical":2,"max_cvss":9.8,"max_epss":0.0089,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-9193","cvss":9.9,"epss":0.0046,"slug":"cve-2026-9193-progress-marklogic-server-privilege-escalation-in-hadoop","title":"Progress MarkLogic Server privilege escalation in Hadoop integration","severity":"critical","exploited":false,"published_at":"2026-08-05T16:17:10.183+00:00","url":"https://junglewise.ai/threats/cve-2026-9193-progress-marklogic-server-privilege-escalation-in-hadoop"},{"cve":"CVE-2026-8709","cvss":9.9,"epss":0.0046,"slug":"cve-2026-8709-progress-marklogic-server-rest-api-privilege-escalation-in","title":"Progress MarkLogic Server REST API privilege escalation in document patch","severity":"critical","exploited":false,"published_at":"2026-08-05T16:17:09.82+00:00","url":"https://junglewise.ai/threats/cve-2026-8709-progress-marklogic-server-rest-api-privilege-escalation-in"},{"cve":"CVE-2026-7329","cvss":9.9,"epss":0.0057,"slug":"cve-2026-7329-progress-marklogic-server-privilege-escalation-in-query-interfaces","title":"Progress MarkLogic Server privilege escalation in query interfaces","severity":"critical","exploited":false,"published_at":"2026-08-05T16:17:09.2+00:00","url":"https://junglewise.ai/threats/cve-2026-7329-progress-marklogic-server-privilege-escalation-in-query-interfaces"}],"high":3,"name":"Progress Marklogic Server","rank":5,"slug":"marklogic-server","score":51,"vendor":{"name":"Progress","slug":"progress"},"critical":7,"max_cvss":9.9,"max_epss":0.0084,"exploited":0,"vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/marklogic-server"},{"hub":true,"top":[{"cve":"CVE-2026-24254","cvss":9.8,"epss":0.0089,"slug":"cve-2026-24254-nvidia-dynamo-for-linux-out-of-bounds-write-in-multimodal-serving","title":"NVIDIA Dynamo for Linux out-of-bounds write in multimodal serving topology","severity":"critical","exploited":false,"published_at":"2026-08-04T18:16:49.937+00:00","url":"https://junglewise.ai/threats/cve-2026-24254-nvidia-dynamo-for-linux-out-of-bounds-write-in-multimodal-serving"},{"cve":"CVE-2026-47623","cvss":8.2,"epss":0.0069,"slug":"cve-2026-47623-nvidia-dynamo-for-linux-deserialization-vulnerability","title":"NVIDIA Dynamo for Linux deserialization vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T18:16:51.983+00:00","url":"https://junglewise.ai/threats/cve-2026-47623-nvidia-dynamo-for-linux-deserialization-vulnerability"},{"cve":"CVE-2026-24253","cvss":8.2,"epss":0.0064,"slug":"cve-2026-24253-nvidia-dynamo-for-linux-out-of-bounds-write","title":"NVIDIA Dynamo for Linux out-of-bounds write","severity":"high","exploited":false,"published_at":"2026-08-04T18:16:49.767+00:00","url":"https://junglewise.ai/threats/cve-2026-24253-nvidia-dynamo-for-linux-out-of-bounds-write"}],"high":10,"name":"Nvidia Dynamo","rank":6,"slug":"dynamo","score":40,"vendor":{"name":"Nvidia","slug":"nvidia"},"critical":1,"max_cvss":9.8,"max_epss":0.0089,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/dynamo"},{"hub":true,"top":[{"cve":"CVE-2026-48086","cvss":9.9,"epss":0.0044,"slug":"cve-2026-48086-openreception-privilege-escalation-in-role-update-handler","title":"OpenReception privilege escalation in role-update handler","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.593+00:00","url":"https://junglewise.ai/threats/cve-2026-48086-openreception-privilege-escalation-in-role-update-handler"},{"cve":"CVE-2026-48087","cvss":9.8,"epss":0.0057,"slug":"cve-2026-48087-openreception-appointment-booking-webauthn-passkey-injection","title":"OpenReception appointment booking WebAuthn passkey injection","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.75+00:00","url":"https://junglewise.ai/threats/cve-2026-48087-openreception-appointment-booking-webauthn-passkey-injection"},{"cve":"CVE-2026-48088","cvss":9.4,"epss":0.0038,"slug":"cve-2026-48088-openreception-authentication-bypass-in-appointment-crypto-key","title":"OpenReception authentication bypass in appointment crypto key storage","severity":"critical","exploited":false,"published_at":"2026-08-06T22:17:11.893+00:00","url":"https://junglewise.ai/threats/cve-2026-48088-openreception-authentication-bypass-in-appointment-crypto-key"}],"high":3,"name":"OpenReception Appointment-Booking-Software","rank":7,"slug":"appointment-booking-software","score":35,"vendor":{"name":"OpenReception","slug":"openreception"},"critical":3,"max_cvss":9.9,"max_epss":0.0057,"exploited":0,"vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/appointment-booking-software"},{"hub":true,"top":[{"cve":"CVE-2026-59650","cvss":9.1,"epss":0.0045,"slug":"cve-2026-59650-bouncy-castle-mti-a0-dh-agreement-unvalidated-peer-value","title":"Bouncy Castle MTI/A0 DH agreement unvalidated peer value","severity":"critical","exploited":false,"published_at":"2026-08-03T01:16:45.25+00:00","url":"https://junglewise.ai/threats/cve-2026-59650-bouncy-castle-mti-a0-dh-agreement-unvalidated-peer-value"},{"cve":"CVE-2026-12185","cvss":8.6,"epss":0.0029,"slug":"cve-2026-12185-bouncy-castle-for-java-bks-uber-keystore-memory-allocation-dos","title":"Bouncy Castle for Java BKS/UBER keystore memory allocation DoS","severity":"high","exploited":false,"published_at":"2026-08-03T01:16:42.987+00:00","url":"https://junglewise.ai/threats/cve-2026-12185-bouncy-castle-for-java-bks-uber-keystore-memory-allocation-dos"},{"cve":"CVE-2026-15055","cvss":8.2,"epss":0.0034,"slug":"cve-2026-15055-bouncy-castle-pkcs-8-pbes2-unbounded-kdf-cost-vulnerability","title":"Bouncy Castle PKCS#8 PBES2 unbounded KDF cost vulnerability","severity":"high","exploited":false,"published_at":"2026-08-03T01:16:43.157+00:00","url":"https://junglewise.ai/threats/cve-2026-15055-bouncy-castle-pkcs-8-pbes2-unbounded-kdf-cost-vulnerability"}],"high":8,"name":"Bouncy Castle for Java","rank":8,"slug":"bouncy-castle-for-java","score":32,"vendor":{"name":"Bouncy Castle","slug":"bouncy-castle"},"critical":1,"max_cvss":9.1,"max_epss":0.0062,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/bouncy-castle-for-java"},{"hub":true,"top":[{"cve":"CVE-2026-70492","cvss":8.7,"epss":0.004,"slug":"cve-2026-70492-open-webui-stored-xss-in-katex-render-error-fallback","title":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Mess","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:38.19+00:00","url":"https://junglewise.ai/threats/cve-2026-70492-open-webui-stored-xss-in-katex-render-error-fallback"},{"cve":"CVE-2026-70486","cvss":8.2,"epss":0.0038,"slug":"cve-2026-70486-open-webui-same-origin-xss-in-terminal-file-preview","title":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview ser","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:55.747+00:00","url":"https://junglewise.ai/threats/cve-2026-70486-open-webui-same-origin-xss-in-terminal-file-preview"},{"cve":"CVE-2026-70494","cvss":8.1,"epss":0.0055,"slug":"cve-2026-70494-open-webui-incorrect-authorization-in-shared-folder-deletion","title":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:38.47+00:00","url":"https://junglewise.ai/threats/cve-2026-70494-open-webui-incorrect-authorization-in-shared-folder-deletion"}],"high":6,"name":"Pip Open-Webui","rank":9,"slug":"open-webui","score":29,"vendor":{"name":"Pip","slug":"pip"},"critical":0,"max_cvss":8.7,"max_epss":0.0059,"exploited":0,"vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"hub":true,"top":[{"cve":"CVE-2026-67862","cvss":7.5,"epss":0.0058,"slug":"cve-2026-67862-open62541-heap-buffer-overflow-in-high-level-attribute-reading","title":"open62541 heap-buffer-overflow in high-level attribute reading","severity":"high","exploited":false,"published_at":"2026-08-04T22:17:16.597+00:00","url":"https://junglewise.ai/threats/cve-2026-67862-open62541-heap-buffer-overflow-in-high-level-attribute-reading"},{"cve":"CVE-2026-67861","cvss":7.5,"epss":0.0075,"slug":"cve-2026-67861-open62541-stack-overflow-in-ua-client-getremotedatatypes","title":"open62541 stack overflow in UA_Client_getRemoteDataTypes","severity":"high","exploited":false,"published_at":"2026-08-04T22:17:16.46+00:00","url":"https://junglewise.ai/threats/cve-2026-67861-open62541-stack-overflow-in-ua-client-getremotedatatypes"},{"cve":"CVE-2026-67860","cvss":7.5,"epss":0.0046,"slug":"cve-2026-67860-open62541-heap-buffer-overflow-in-historyread-continuation-point","title":"open62541 heap buffer overflow in HistoryRead continuation point handling","severity":"high","exploited":false,"published_at":"2026-08-04T22:17:16.357+00:00","url":"https://junglewise.ai/threats/cve-2026-67860-open62541-heap-buffer-overflow-in-historyread-continuation-point"}],"high":8,"name":"Open62541 Project Open62541","rank":10,"slug":"open62541","score":26,"vendor":{"name":"Open62541 Project","slug":"open62541-project"},"critical":0,"max_cvss":7.5,"max_epss":0.0086,"exploited":0,"vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/open62541"},{"hub":true,"top":[{"cvss":10,"slug":"siyuan-sql-injection-in-fulltextsearchassetcontent-endpoint-77bd29ce","title":"SiYuan SQL injection in fullTextSearchAssetContent endpoint","severity":"critical","exploited":false,"published_at":"2026-08-03T15:32:48+00:00","url":"https://junglewise.ai/threats/siyuan-sql-injection-in-fulltextsearchassetcontent-endpoint-77bd29ce"},{"cvss":10,"slug":"siyuan-searchembedblock-sql-injection-1301810a","title":"SiYuan searchEmbedBlock SQL injection","severity":"critical","exploited":false,"published_at":"2026-08-03T15:32:48+00:00","url":"https://junglewise.ai/threats/siyuan-searchembedblock-sql-injection-1301810a"},{"cvss":8.6,"slug":"siyuan-authentication-bypass-in-publish-mode-content-endpoints-f588ab5f","title":"SiYuan authentication bypass in publish mode content endpoints","severity":"high","exploited":false,"published_at":"2026-08-03T15:32:47+00:00","url":"https://junglewise.ai/threats/siyuan-authentication-bypass-in-publish-mode-content-endpoints-f588ab5f"}],"high":4,"name":"SiYuan","rank":11,"slug":"siyuan","score":26,"vendor":{"name":"SiYuan","slug":"siyuan"},"critical":2,"max_cvss":10,"max_epss":null,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/siyuan"},{"hub":true,"top":[{"cve":"CVE-2026-45538","cvss":9.8,"epss":0.008,"slug":"cve-2026-45538-opensips-stack-buffer-overflow-in-sip-to-json-header-parsing","title":"OpenSIPS stack buffer overflow in sip_to_json header parsing","severity":"critical","exploited":false,"published_at":"2026-08-04T21:16:36.27+00:00","url":"https://junglewise.ai/threats/cve-2026-45538-opensips-stack-buffer-overflow-in-sip-to-json-header-parsing"},{"cve":"CVE-2026-45537","cvss":9.1,"epss":0.0063,"slug":"cve-2026-45537-opensips-construct-uri-buffer-overflow","title":"OpenSIPS construct_uri buffer overflow","severity":"critical","exploited":false,"published_at":"2026-08-04T23:16:51.687+00:00","url":"https://junglewise.ai/threats/cve-2026-45537-opensips-construct-uri-buffer-overflow"},{"cve":"CVE-2026-45100","cvss":9.1,"epss":0.0083,"slug":"cve-2026-45100-opensips-buffer-overflow-in-b64encode-string-transformation","title":"OpenSIPS buffer overflow in b64encode string transformation","severity":"critical","exploited":false,"published_at":"2026-08-04T22:17:14.67+00:00","url":"https://junglewise.ai/threats/cve-2026-45100-opensips-buffer-overflow-in-b64encode-string-transformation"}],"high":1,"name":"OpenSIPS","rank":12,"slug":"opensips","score":25,"vendor":{"name":"OpenSIPS","slug":"opensips"},"critical":3,"max_cvss":9.8,"max_epss":0.0083,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/opensips"},{"hub":true,"top":[{"cve":"CVE-2026-18810","cvss":7.3,"epss":0.0065,"slug":"cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api","title":"H3C NX15 authentication bypass in network setup API","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:51.36+00:00","url":"https://junglewise.ai/threats/cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api"},{"cve":"CVE-2026-18902","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration","title":"H3C NX15 command injection in WAN repeater configuration","severity":"high","exploited":false,"published_at":"2026-08-05T06:16:37.49+00:00","url":"https://junglewise.ai/threats/cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration"},{"cve":"CVE-2026-18901","cvss":7.2,"epss":0.0085,"slug":"cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api","title":"H3C NX15 dangerous routine exposure in Web API","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.433+00:00","url":"https://junglewise.ai/threats/cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api"}],"high":8,"name":"H3C NX15","rank":13,"slug":"nx15","score":24,"vendor":{"name":"H3C","slug":"h3c"},"critical":0,"max_cvss":7.3,"max_epss":0.0382,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/nx15"},{"hub":true,"top":[{"cve":"CVE-2026-5430","cvss":10,"epss":0.0058,"slug":"cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability","title":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an a","severity":"critical","exploited":true,"published_at":"2026-08-06T08:16:33.24+00:00","url":"https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability"},{"cve":"CVE-2025-14561","cvss":9,"epss":0.0041,"slug":"cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant","title":"WSO2 Publisher REST APIs tenant isolation bypass in multi-tenant deployments","severity":"critical","exploited":false,"published_at":"2026-08-06T22:16:41.42+00:00","url":"https://junglewise.ai/threats/cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant"},{"cve":"CVE-2024-6541","cvss":6.8,"epss":0.0034,"slug":"cve-2024-6541-wso2-class-mediator-improper-messagecontext-validation","title":"WSO2 Class Mediator improper messageContext validation","severity":"medium","exploited":false,"published_at":"2026-08-06T22:16:40.557+00:00","url":"https://junglewise.ai/threats/cve-2024-6541-wso2-class-mediator-improper-messagecontext-validation"}],"high":0,"name":"Wso2 API Manager","rank":14,"slug":"api-manager","score":24,"vendor":{"name":"Wso2","slug":"wso2"},"critical":2,"max_cvss":10,"max_epss":0.0058,"exploited":1,"vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/api-manager"},{"hub":true,"top":[{"cve":"CVE-2026-71986","cvss":9.8,"epss":0.0246,"slug":"cve-2026-71986-msi-radix-axe6600-command-injection-in-dmz-function","title":"MSI Radix AXE6600 command injection in DMZ function","severity":"critical","exploited":false,"published_at":"2026-08-09T00:16:47.5+00:00","url":"https://junglewise.ai/threats/cve-2026-71986-msi-radix-axe6600-command-injection-in-dmz-function"},{"cve":"CVE-2026-71985","cvss":9.8,"epss":0.0246,"slug":"cve-2026-71985-msi-radix-axe6600-command-injection-in-accesscontrol-function","title":"MSI RadiX AXE6600 command injection in accesscontrol function","severity":"critical","exploited":false,"published_at":"2026-08-09T00:16:47.36+00:00","url":"https://junglewise.ai/threats/cve-2026-71985-msi-radix-axe6600-command-injection-in-accesscontrol-function"},{"cve":"CVE-2026-71984","cvss":9.8,"epss":0.0246,"slug":"cve-2026-71984-msi-radix-axe6600-command-injection-in-urlfilter-function","title":"MSI Radix AXE6600 command injection in urlfilter function","severity":"critical","exploited":false,"published_at":"2026-08-09T00:16:47.207+00:00","url":"https://junglewise.ai/threats/cve-2026-71984-msi-radix-axe6600-command-injection-in-urlfilter-function"}],"high":0,"name":"MSI Radix AXE6600","rank":15,"slug":"radix-axe6600","score":24,"vendor":{"name":"MSI","slug":"msi"},"critical":4,"max_cvss":9.8,"max_epss":0.0246,"exploited":0,"vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/radix-axe6600"},{"hub":true,"top":[{"cve":"CVE-2026-59650","cvss":9.1,"epss":0.0045,"slug":"cve-2026-59650-bouncy-castle-mti-a0-dh-agreement-unvalidated-peer-value","title":"Bouncy Castle MTI/A0 DH agreement unvalidated peer value","severity":"critical","exploited":false,"published_at":"2026-08-03T01:16:45.25+00:00","url":"https://junglewise.ai/threats/cve-2026-59650-bouncy-castle-mti-a0-dh-agreement-unvalidated-peer-value"},{"cve":"CVE-2026-12185","cvss":8.6,"epss":0.0029,"slug":"cve-2026-12185-bouncy-castle-for-java-bks-uber-keystore-memory-allocation-dos","title":"Bouncy Castle for Java BKS/UBER keystore memory allocation DoS","severity":"high","exploited":false,"published_at":"2026-08-03T01:16:42.987+00:00","url":"https://junglewise.ai/threats/cve-2026-12185-bouncy-castle-for-java-bks-uber-keystore-memory-allocation-dos"},{"cve":"CVE-2026-15055","cvss":8.2,"epss":0.0034,"slug":"cve-2026-15055-bouncy-castle-pkcs-8-pbes2-unbounded-kdf-cost-vulnerability","title":"Bouncy Castle PKCS#8 PBES2 unbounded KDF cost vulnerability","severity":"high","exploited":false,"published_at":"2026-08-03T01:16:43.157+00:00","url":"https://junglewise.ai/threats/cve-2026-15055-bouncy-castle-pkcs-8-pbes2-unbounded-kdf-cost-vulnerability"}],"high":5,"name":"Bouncycastle Bouncy Castle For Java Lts","rank":16,"slug":"bouncy-castle-for-java-lts","score":23,"vendor":{"name":"Bouncycastle","slug":"bouncycastle"},"critical":1,"max_cvss":9.1,"max_epss":0.0045,"exploited":0,"vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/bouncy-castle-for-java-lts"},{"hub":true,"top":[{"cve":"CVE-2026-24254","cvss":9.8,"epss":0.0089,"slug":"cve-2026-24254-nvidia-dynamo-for-linux-out-of-bounds-write-in-multimodal-serving","title":"NVIDIA Dynamo for Linux out-of-bounds write in multimodal serving topology","severity":"critical","exploited":false,"published_at":"2026-08-04T18:16:49.937+00:00","url":"https://junglewise.ai/threats/cve-2026-24254-nvidia-dynamo-for-linux-out-of-bounds-write-in-multimodal-serving"},{"cve":"CVE-2026-47623","cvss":8.2,"epss":0.0069,"slug":"cve-2026-47623-nvidia-dynamo-for-linux-deserialization-vulnerability","title":"NVIDIA Dynamo for Linux deserialization vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T18:16:51.983+00:00","url":"https://junglewise.ai/threats/cve-2026-47623-nvidia-dynamo-for-linux-deserialization-vulnerability"},{"cve":"CVE-2026-24253","cvss":8.2,"epss":0.0064,"slug":"cve-2026-24253-nvidia-dynamo-for-linux-out-of-bounds-write","title":"NVIDIA Dynamo for Linux out-of-bounds write","severity":"high","exploited":false,"published_at":"2026-08-04T18:16:49.767+00:00","url":"https://junglewise.ai/threats/cve-2026-24253-nvidia-dynamo-for-linux-out-of-bounds-write"}],"high":5,"name":"Nvidia Dynamo for Linux","rank":17,"slug":"dynamo-for-linux","score":22,"vendor":{"name":"Nvidia","slug":"nvidia"},"critical":1,"max_cvss":9.8,"max_epss":0.0089,"exploited":0,"vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/dynamo-for-linux"},{"hub":true,"top":[{"cve":"CVE-2026-5430","cvss":10,"epss":0.0058,"slug":"cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability","title":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an a","severity":"critical","exploited":true,"published_at":"2026-08-06T08:16:33.24+00:00","url":"https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability"},{"cve":"CVE-2025-14561","cvss":9,"epss":0.0041,"slug":"cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant","title":"WSO2 Publisher REST APIs tenant isolation bypass in multi-tenant deployments","severity":"critical","exploited":false,"published_at":"2026-08-06T22:16:41.42+00:00","url":"https://junglewise.ai/threats/cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant"}],"high":0,"name":"Wso2 API Control Plane","rank":18,"slug":"api-control-plane","score":22,"vendor":{"name":"Wso2","slug":"wso2"},"critical":2,"max_cvss":10,"max_epss":0.0058,"exploited":1,"vulnerabilities":2,"url":"https://junglewise.ai/threats/technologies/api-control-plane"},{"hub":true,"top":[{"cve":"CVE-2026-5430","cvss":10,"epss":0.0058,"slug":"cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability","title":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an a","severity":"critical","exploited":true,"published_at":"2026-08-06T08:16:33.24+00:00","url":"https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability"},{"cve":"CVE-2025-14561","cvss":9,"epss":0.0041,"slug":"cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant","title":"WSO2 Publisher REST APIs tenant isolation bypass in multi-tenant deployments","severity":"critical","exploited":false,"published_at":"2026-08-06T22:16:41.42+00:00","url":"https://junglewise.ai/threats/cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant"}],"high":0,"name":"Wso2 Traffic Manager","rank":19,"slug":"traffic-manager","score":22,"vendor":{"name":"Wso2","slug":"wso2"},"critical":2,"max_cvss":10,"max_epss":0.0058,"exploited":1,"vulnerabilities":2,"url":"https://junglewise.ai/threats/technologies/traffic-manager"},{"hub":true,"top":[{"cve":"CVE-2026-5430","cvss":10,"epss":0.0058,"slug":"cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability","title":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an a","severity":"critical","exploited":true,"published_at":"2026-08-06T08:16:33.24+00:00","url":"https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability"},{"cve":"CVE-2025-14561","cvss":9,"epss":0.0041,"slug":"cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant","title":"WSO2 Publisher REST APIs tenant isolation bypass in multi-tenant deployments","severity":"critical","exploited":false,"published_at":"2026-08-06T22:16:41.42+00:00","url":"https://junglewise.ai/threats/cve-2025-14561-wso2-publisher-rest-apis-tenant-isolation-bypass-in-multi-tenant"}],"high":0,"name":"Wso2 Universal Gateway","rank":20,"slug":"universal-gateway","score":22,"vendor":{"name":"Wso2","slug":"wso2"},"critical":2,"max_cvss":10,"max_epss":0.0058,"exploited":1,"vulnerabilities":2,"url":"https://junglewise.ai/threats/technologies/universal-gateway"},{"hub":true,"top":[{"cvss":8.8,"slug":"gitpython-command-execution-via-short-option-smuggling-bypass-37730e44","title":"GitPython command execution via short-option smuggling bypass","severity":"high","exploited":false,"published_at":"2026-08-07T15:49:07+00:00","url":"https://junglewise.ai/threats/gitpython-command-execution-via-short-option-smuggling-bypass-37730e44"},{"cvss":8.8,"slug":"gitpython-rce-via-git-config-option-name-injection-a2291ba6","title":"GitPython RCE via git-config option name injection","severity":"high","exploited":false,"published_at":"2026-08-07T15:46:35+00:00","url":"https://junglewise.ai/threats/gitpython-rce-via-git-config-option-name-injection-a2291ba6"},{"cvss":8.2,"slug":"gitpython-path-traversal-via-unvalidated-submodule-name-287f9026","title":"GitPython path traversal via unvalidated submodule name","severity":"high","exploited":false,"published_at":"2026-08-07T15:45:39+00:00","url":"https://junglewise.ai/threats/gitpython-path-traversal-via-unvalidated-submodule-name-287f9026"}],"high":6,"name":"Gitpython Project Gitpython","rank":21,"slug":"gitpython","score":21,"vendor":{"name":"Gitpython Project","slug":"gitpython-project"},"critical":0,"max_cvss":8.8,"max_epss":null,"exploited":0,"vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/gitpython"},{"hub":true,"top":[{"cve":"CVE-2026-20272","cvss":9.8,"epss":0.0057,"slug":"cve-2026-20272-cisco-ios-xe-software-improper-neutralization-of-special-elements","title":"Cisco IOS XE Software improper neutralization of special elements","severity":"critical","exploited":false,"published_at":"2026-08-05T17:16:49.053+00:00","url":"https://junglewise.ai/threats/cve-2026-20272-cisco-ios-xe-software-improper-neutralization-of-special-elements"},{"cve":"CVE-2026-20273","cvss":8.6,"epss":0.0047,"slug":"cve-2026-20273-cisco-ios-xe-software-improper-input-validation","title":"Cisco IOS XE Software improper input validation","severity":"high","exploited":false,"published_at":"2026-08-05T17:16:49.29+00:00","url":"https://junglewise.ai/threats/cve-2026-20273-cisco-ios-xe-software-improper-input-validation"},{"cve":"CVE-2026-20271","cvss":8.6,"epss":0.0047,"slug":"cve-2026-20271-cisco-ios-xe-insufficient-control-flow-management","title":"Cisco IOS XE insufficient control flow management","severity":"high","exploited":false,"published_at":"2026-08-05T17:16:48.81+00:00","url":"https://junglewise.ai/threats/cve-2026-20271-cisco-ios-xe-insufficient-control-flow-management"}],"high":5,"name":"Cisco IOS XE","rank":22,"slug":"ios-xe","score":21,"vendor":{"name":"Cisco","slug":"cisco"},"critical":1,"max_cvss":9.8,"max_epss":0.0057,"exploited":0,"vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ios-xe"},{"hub":true,"top":[{"cve":"CVE-2026-66318","cvss":8.1,"epss":0.0036,"slug":"cve-2026-66318-microsoft-edge-origin-validation-error-allows-information","title":"Microsoft Edge origin validation error allows information disclosure","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.317+00:00","url":"https://junglewise.ai/threats/cve-2026-66318-microsoft-edge-origin-validation-error-allows-information"},{"cve":"CVE-2026-66315","cvss":7.5,"epss":0.0061,"slug":"cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium","title":"Microsoft Edge use-after-free vulnerability in Chromium","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:38.927+00:00","url":"https://junglewise.ai/threats/cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium"},{"cve":"CVE-2026-66321","cvss":7.4,"epss":0.0107,"slug":"cve-2026-66321-microsoft-edge-type-confusion-vulnerability","title":"Microsoft Edge type confusion vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.44+00:00","url":"https://junglewise.ai/threats/cve-2026-66321-microsoft-edge-type-confusion-vulnerability"}],"high":4,"name":"Microsoft Edge Chromium","rank":23,"slug":"edge-chromium","score":19,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":0,"max_cvss":8.1,"max_epss":0.011,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/edge-chromium"},{"hub":true,"top":[{"cve":"CVE-2026-66318","cvss":8.1,"epss":0.0036,"slug":"cve-2026-66318-microsoft-edge-origin-validation-error-allows-information","title":"Microsoft Edge origin validation error allows information disclosure","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.317+00:00","url":"https://junglewise.ai/threats/cve-2026-66318-microsoft-edge-origin-validation-error-allows-information"},{"cve":"CVE-2026-66315","cvss":7.5,"epss":0.0061,"slug":"cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium","title":"Microsoft Edge use-after-free vulnerability in Chromium","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:38.927+00:00","url":"https://junglewise.ai/threats/cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium"},{"cve":"CVE-2026-66321","cvss":7.4,"epss":0.0107,"slug":"cve-2026-66321-microsoft-edge-type-confusion-vulnerability","title":"Microsoft Edge type confusion vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.44+00:00","url":"https://junglewise.ai/threats/cve-2026-66321-microsoft-edge-type-confusion-vulnerability"}],"high":4,"name":"Microsoft Edge","rank":24,"slug":"edge-chromium-based","score":19,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":0,"max_cvss":8.1,"max_epss":0.011,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"hub":true,"top":[{"cve":"CVE-2026-5430","cvss":10,"epss":0.0058,"slug":"cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability","title":"The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an a","severity":"critical","exploited":true,"published_at":"2026-08-06T08:16:33.24+00:00","url":"https://junglewise.ai/threats/cve-2026-5430-wso2-api-control-plane-path-traversal-vulnerability"},{"cve":"CVE-2024-6541","cvss":6.8,"epss":0.0034,"slug":"cve-2024-6541-wso2-class-mediator-improper-messagecontext-validation","title":"WSO2 Class Mediator improper messageContext validation","severity":"medium","exploited":false,"published_at":"2026-08-06T22:16:40.557+00:00","url":"https://junglewise.ai/threats/cve-2024-6541-wso2-class-mediator-improper-messagecontext-validation"},{"cve":"CVE-2025-12317","cvss":5,"epss":0.0025,"slug":"cve-2025-12317-wso2-identity-server-improper-token-revocation-via-soap-services","title":"WSO2 Identity Server improper token revocation via SOAP services","severity":"medium","exploited":false,"published_at":"2026-08-06T22:16:41.28+00:00","url":"https://junglewise.ai/threats/cve-2025-12317-wso2-identity-server-improper-token-revocation-via-soap-services"}],"high":0,"name":"Wso2 Enterprise Integrator","rank":25,"slug":"enterprise-integrator","score":18,"vendor":{"name":"Wso2","slug":"wso2"},"critical":1,"max_cvss":10,"max_epss":0.0058,"exploited":1,"vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/enterprise-integrator"}],"previous":{"key":"2026-07-27","top":"Google Chrome","period":{"end":"2026-08-02","start":"2026-07-27"},"totals":{"high":426,"critical":114,"exploited":7,"technologies":1027,"vulnerabilities":2117},"url":"https://junglewise.ai/threats/weekly/2026-07-27"},"next":{"key":"2026-08-10","top":"Linux Kernel","period":{"end":"2026-08-16","start":"2026-08-10"},"totals":{"high":789,"critical":222,"exploited":6,"technologies":951,"vulnerabilities":1900},"url":"https://junglewise.ai/threats/weekly/2026-08-10"}}