Junglewise

Weekly report

Most vulnerable technologies: week of 17 to 23 August 2026 (week 34)

Final report, published . It does not change.

In the week of 17 to 23 August 2026, Junglewise Threat Intelligence recorded 2,072 new vulnerabilities: 270 critical, 829 high and 4 exploited in the wild. The most vulnerable technology was Linux Kernel, with 158 vulnerabilities (22 critical), followed by IBM AIX (72) and IBM PowerVM VIOS (72).

New vulnerabilities
2,072
Critical
270
Exploited in the wild
4
Technologies affected
912

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Linux Kernel
Linux
1582285010
2IBM AIX
IBM
72124209.9
3IBM PowerVM VIOS
IBM
72124209.9
4Mozilla Thunderbird
Mozilla
521525010
5Mozilla Firefox
Mozilla
521425010
6Mozilla Firefox ESR
Mozilla
491225010
7Oracle Helidon
Oracle
5561909.8
8Oracle Hyperion Data Relationship Management
Oracle
35726010
9Oracle Commerce Experience Manager
Oracle
4072109.3
10Oracle Commerce Guided Search
Oracle
4072109.3
11Oracle Hyperion Financial Management
Oracle
49318010
12Npm Orval
Npm
1211107.1
13Apache CloudStack
Apache
2031209.1
14Go Github.com/Lxc/Incus/V7/Cmd/Incusd
Go
107109.9
15Pip Nltk
Pip
2201108.8
16Combodo iTop
Combodo
1801308.8
17Mozilla Thunderbird-Esr
Mozilla
1246010
18N8n
N8n
172809.8
19ArcadeData ArcadeDB
ArcadeData
134509.9
20IBM Power Systems Firmware
IBM
122909.6
21Apple macOS
Apple
310408.8
22Oracle VirtualBox
Oracle
210908.6
23Apple iPadOS
Apple
300308.8
24NLTK Project Natural Language Toolkit
NLTK Project
190808.8
25Pip Justhtml
Pip
123309.8

Most affected vendors

  1. 1.Oracle294 vulnerabilities, 31 critical, 0 exploited
  2. 2.Linux158 vulnerabilities, 22 critical, 0 exploited
  3. 3.IBM86 vulnerabilities, 14 critical, 0 exploited
  4. 4.Pip90 vulnerabilities, 5 critical, 1 exploited
  5. 5.Mozilla55 vulnerabilities, 15 critical, 0 exploited
  6. 6.Npm56 vulnerabilities, 15 critical, 0 exploited
  7. 7.Go49 vulnerabilities, 10 critical, 0 exploited
  8. 8.Microsoft23 vulnerabilities, 12 critical, 0 exploited
  9. 9.Apache31 vulnerabilities, 6 critical, 0 exploited
  10. 10.Splunk50 vulnerabilities, 1 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/weekly/2026-08-17.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 17 to 23 August 2026 (week 34)", https://junglewise.ai/threats/weekly/2026-08-17, 26 September 2026.