Weekly report
Most vulnerable technologies: week of 17 to 23 August 2026 (week 34)
Final report, published . It does not change.
In the week of 17 to 23 August 2026, Junglewise Threat Intelligence recorded 2,072 new vulnerabilities: 270 critical, 829 high and 4 exploited in the wild. The most vulnerable technology was Linux Kernel, with 158 vulnerabilities (22 critical), followed by IBM AIX (72) and IBM PowerVM VIOS (72).
- New vulnerabilities
- 2,072
- Critical
- 270
- Exploited in the wild
- 4
- Technologies affected
- 912
Ranking
Most affected vendors
- 1.Oracle294 vulnerabilities, 31 critical, 0 exploited
- 2.Linux158 vulnerabilities, 22 critical, 0 exploited
- 3.IBM86 vulnerabilities, 14 critical, 0 exploited
- 4.Pip90 vulnerabilities, 5 critical, 1 exploited
- 5.Mozilla55 vulnerabilities, 15 critical, 0 exploited
- 6.Npm56 vulnerabilities, 15 critical, 0 exploited
- 7.Go49 vulnerabilities, 10 critical, 0 exploited
- 8.Microsoft23 vulnerabilities, 12 critical, 0 exploited
- 9.Apache31 vulnerabilities, 6 critical, 0 exploited
- 10.Splunk50 vulnerabilities, 1 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-73570: Zimbra Collaboration Suite OS command injection in SMTPcriticalexploited in the wildCVSS 9.8EPSS 11.7%
- CVE-2026-72529: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X…criticalexploited in the wildCVSS 9.8EPSS 1.5%
- CVE-2026-64849: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to…criticalexploited in the wildCVSS 9.3EPSS 9.8%
- CVE-2026-72530: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X…criticalexploited in the wildCVSS 9EPSS 1.7%
- CVE-2026-69836: Microsoft Entra ID deserialization of untrusted data remote code executioncriticalCVSS 10EPSS 1.5%
- CVE-2026-19977: EFM ipTIME A3004T authentication bypass in session validationcriticalCVSS 10EPSS 1.3%
- CVE-2026-61539: Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference…criticalCVSS 10EPSS 1.2%
- CVE-2026-65770: Microsoft Azure Managed Instance for Apache Cassandra argument injectioncriticalCVSS 10EPSS 1.1%
- CVE-2026-77946: TRENDnet TEW-821DAP stack-based buffer overflow in NTP timezone configurationcriticalCVSS 10EPSS 1.0%
- CVE-2026-65816: Microsoft Azure Arc name resolution privilege escalationcriticalCVSS 10EPSS 1.0%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-08-17.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 17 to 23 August 2026 (week 34)", https://junglewise.ai/threats/weekly/2026-08-17, 26 September 2026.