Weekly report
Most vulnerable technologies: week of 10 to 16 August 2026 (week 33)
Final report, published . It does not change.
In the week of 10 to 16 August 2026, Junglewise Threat Intelligence recorded 1,900 new vulnerabilities: 222 critical, 789 high and 6 exploited in the wild. The most vulnerable technology was Linux Kernel, with 546 vulnerabilities (82 critical), followed by SiYuan (37) and IBM i (37).
- New vulnerabilities
- 1,900
- Critical
- 222
- Exploited in the wild
- 6
- Technologies affected
- 951
Ranking
Most affected vendors
- 1.Linux546 vulnerabilities, 82 critical, 0 exploited
- 2.Microsoft175 vulnerabilities, 5 critical, 2 exploited
- 3.IBM68 vulnerabilities, 6 critical, 0 exploited
- 4.Intel59 vulnerabilities, 0 critical, 0 exploited
- 5.SiYuan35 vulnerabilities, 7 critical, 0 exploited
- 6.Adobe22 vulnerabilities, 4 critical, 1 exploited
- 7.Apache26 vulnerabilities, 7 critical, 0 exploited
- 8.Go29 vulnerabilities, 3 critical, 0 exploited
- 9.Npm36 vulnerabilities, 1 critical, 0 exploited
- 10.Siemens17 vulnerabilities, 1 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-72898: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and…criticalexploited in the wildCVSS 10EPSS 19.1%
- CVE-2026-71362: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An…criticalexploited in the wildCVSS 9.1EPSS 89.6%
- CVE-2026-65660: Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to…criticalexploited in the wildCVSS 8.8EPSS 1.2%
- CVE-2026-20349: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software…criticalexploited in the wildCVSS 8.6EPSS 1.0%
- CVE-2026-68820: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.criticalexploited in the wildCVSS 7EPSS 0.3%
- CVE-2026-66384: An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.criticalexploited in the wildCVSS 5.3EPSS 0.7%
- CVE-2026-19188: Haiwell IoT Cloud HMI Gateway OS command injectioncriticalCVSS 10EPSS 2.9%
- CVE-2026-73678: MindsDB Minds Platform unauthenticated remote code execution in agent scratchpadcriticalCVSS 10EPSS 1.6%
- CVE-2026-71398: Adobe Campaign Classic authorization bypass leading to code executioncriticalCVSS 10EPSS 1.2%
- CVE-2026-27302: Adobe Campaign Classic authorization bypass leading to code executioncriticalCVSS 10EPSS 1.2%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-08-10.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 10 to 16 August 2026 (week 33)", https://junglewise.ai/threats/weekly/2026-08-10, 26 September 2026.