{"schema_version":1,"title":"Most vulnerable technologies: week of 17 to 23 August 2026 (week 34)","summary":"In the week of 17 to 23 August 2026, Junglewise Threat Intelligence recorded 2,072 new vulnerabilities: 270 critical, 829 high and 4 exploited in the wild. The most vulnerable technology was Linux Kernel, with 158 vulnerabilities (22 critical), followed by IBM AIX (72) and IBM PowerVM VIOS (72).","url":"https://junglewise.ai/threats/weekly/2026-08-17","json_url":"https://junglewise.ai/threats/weekly/2026-08-17.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/weekly/2026-08-17","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"week","period":{"end":"2026-08-23","start":"2026-08-17"},"totals":{"high":829,"critical":270,"exploited":4,"technologies":912,"vulnerabilities":2072},"notable":[{"cve":"CVE-2026-73570","cvss":9.8,"epss":0.1174,"slug":"cve-2026-73570-zimbra-collaboration-suite-os-command-injection-in-smtp","title":"Zimbra Collaboration Suite OS command injection in SMTP","severity":"critical","exploited":true,"published_at":"2026-08-21T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-73570-zimbra-collaboration-suite-os-command-injection-in-smtp"},{"cve":"CVE-2026-72529","cvss":9.8,"epss":0.0146,"slug":"cve-2026-72529-trueconf-server-missing-authentication-for-critical-function","title":"A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t","severity":"critical","exploited":true,"published_at":"2026-08-19T17:21:00.99+00:00","url":"https://junglewise.ai/threats/cve-2026-72529-trueconf-server-missing-authentication-for-critical-function"},{"cve":"CVE-2026-64849","cvss":9.3,"epss":0.0984,"slug":"cve-2026-64849-mlflow-server-side-request-forgery","title":"MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauth","severity":"critical","exploited":true,"published_at":"2026-08-17T22:17:23.58+00:00","url":"https://junglewise.ai/threats/cve-2026-64849-mlflow-server-side-request-forgery"},{"cve":"CVE-2026-72530","cvss":9,"epss":0.0169,"slug":"cve-2026-72530-trueconf-server-code-injection-vulnerability","title":"A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X t","severity":"critical","exploited":true,"published_at":"2026-08-19T17:21:01.13+00:00","url":"https://junglewise.ai/threats/cve-2026-72530-trueconf-server-code-injection-vulnerability"},{"cve":"CVE-2026-69836","cvss":10,"epss":0.0153,"slug":"cve-2026-69836-microsoft-entra-id-deserialization-of-untrusted-data-remote-code","title":"Microsoft Entra ID deserialization of untrusted data remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-20T22:18:00.74+00:00","url":"https://junglewise.ai/threats/cve-2026-69836-microsoft-entra-id-deserialization-of-untrusted-data-remote-code"},{"cve":"CVE-2026-19977","cvss":10,"epss":0.0133,"slug":"cve-2026-19977-efm-iptime-a3004t-authentication-bypass-in-session-validation","title":"EFM ipTIME A3004T authentication bypass in session validation","severity":"critical","exploited":false,"published_at":"2026-08-17T03:16:50.517+00:00","url":"https://junglewise.ai/threats/cve-2026-19977-efm-iptime-a3004t-authentication-bypass-in-session-validation"},{"cve":"CVE-2026-61539","cvss":10,"epss":0.0123,"slug":"cve-2026-61539-xinference-remote-code-execution-via-unsafe-eval-in-llama3-tool","title":"Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-infl","severity":"critical","exploited":false,"published_at":"2026-08-21T21:17:00.867+00:00","url":"https://junglewise.ai/threats/cve-2026-61539-xinference-remote-code-execution-via-unsafe-eval-in-llama3-tool"},{"cve":"CVE-2026-65770","cvss":10,"epss":0.0105,"slug":"cve-2026-65770-microsoft-azure-managed-instance-for-apache-cassandra-argument","title":"Microsoft Azure Managed Instance for Apache Cassandra argument injection","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:52.01+00:00","url":"https://junglewise.ai/threats/cve-2026-65770-microsoft-azure-managed-instance-for-apache-cassandra-argument"},{"cve":"CVE-2026-77946","cvss":10,"epss":0.0102,"slug":"cve-2026-77946-trendnet-tew-821dap-stack-based-buffer-overflow-in-ntp-timezone","title":"TRENDnet TEW-821DAP stack-based buffer overflow in NTP timezone configuration","severity":"critical","exploited":false,"published_at":"2026-08-22T11:16:54.447+00:00","url":"https://junglewise.ai/threats/cve-2026-77946-trendnet-tew-821dap-stack-based-buffer-overflow-in-ntp-timezone"},{"cve":"CVE-2026-65816","cvss":10,"epss":0.0097,"slug":"cve-2026-65816-microsoft-azure-arc-name-resolution-privilege-escalation","title":"Microsoft Azure Arc name resolution privilege escalation","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:55.597+00:00","url":"https://junglewise.ai/threats/cve-2026-65816-microsoft-azure-arc-name-resolution-privilege-escalation"}],"vendors":[{"hub":true,"high":167,"name":"Oracle","rank":1,"slug":"oracle","critical":31,"exploited":0,"vulnerabilities":294,"url":"https://junglewise.ai/threats/vendors/oracle"},{"hub":true,"high":85,"name":"Linux","rank":2,"slug":"linux","critical":22,"exploited":0,"vulnerabilities":158,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":52,"name":"IBM","rank":3,"slug":"ibm","critical":14,"exploited":0,"vulnerabilities":86,"url":"https://junglewise.ai/threats/vendors/ibm"},{"hub":true,"high":42,"name":"Pip","rank":4,"slug":"pip","critical":5,"exploited":1,"vulnerabilities":90,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":25,"name":"Mozilla","rank":5,"slug":"mozilla","critical":15,"exploited":0,"vulnerabilities":55,"url":"https://junglewise.ai/threats/vendors/mozilla"},{"hub":true,"high":19,"name":"Npm","rank":6,"slug":"npm","critical":15,"exploited":0,"vulnerabilities":56,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":13,"name":"Go","rank":7,"slug":"go","critical":10,"exploited":0,"vulnerabilities":49,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":9,"name":"Microsoft","rank":8,"slug":"microsoft","critical":12,"exploited":0,"vulnerabilities":23,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":16,"name":"Apache","rank":9,"slug":"apache","critical":6,"exploited":0,"vulnerabilities":31,"url":"https://junglewise.ai/threats/vendors/apache"},{"hub":true,"high":15,"name":"Splunk","rank":10,"slug":"splunk","critical":1,"exploited":0,"vulnerabilities":50,"url":"https://junglewise.ai/threats/vendors/splunk"}],"generated_at":"2026-09-26T09:24:00.138874+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-74705","cvss":10,"epss":0.0073,"slug":"cve-2026-74705-linux-kernel-udp-tunnel-segmentation-use-after-free","title":"Linux kernel UDP tunnel segmentation use-after-free","severity":"critical","exploited":false,"published_at":"2026-08-22T16:16:45.213+00:00","url":"https://junglewise.ai/threats/cve-2026-74705-linux-kernel-udp-tunnel-segmentation-use-after-free"},{"cve":"CVE-2026-74612","cvss":10,"epss":0.0072,"slug":"cve-2026-74612-linux-kernel-veth-xdp-skb-length-accounting-corruption","title":"Linux kernel veth XDP skb length accounting corruption","severity":"critical","exploited":false,"published_at":"2026-08-22T16:16:33.77+00:00","url":"https://junglewise.ai/threats/cve-2026-74612-linux-kernel-veth-xdp-skb-length-accounting-corruption"},{"cve":"CVE-2026-74730","cvss":9.8,"epss":0.0073,"slug":"cve-2026-74730-linux-kernel-nfs-use-after-free-in-free-stateid","title":"Linux kernel NFS use-after-free in FREE_STATEID","severity":"critical","exploited":false,"published_at":"2026-08-22T16:16:48.137+00:00","url":"https://junglewise.ai/threats/cve-2026-74730-linux-kernel-nfs-use-after-free-in-free-stateid"}],"high":85,"name":"Linux Kernel","rank":1,"slug":"kernel","score":438,"vendor":{"name":"Linux","slug":"linux"},"critical":22,"max_cvss":10,"max_epss":0.0076,"exploited":0,"vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-18835","cvss":9.9,"epss":0.0079,"slug":"cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability","title":"IBM AIX and PowerVM VIOS command injection vulnerability","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:17.43+00:00","url":"https://junglewise.ai/threats/cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability"},{"cve":"CVE-2026-17160","cvss":9.8,"epss":0.008,"slug":"cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation","title":"IBM AIX and PowerVM VIOS integer overflow in size computation","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.36+00:00","url":"https://junglewise.ai/threats/cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation"},{"cve":"CVE-2026-17157","cvss":9.8,"epss":0.008,"slug":"cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code","title":"IBM AIX and PowerVM VIOS stack buffer overflow remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.013+00:00","url":"https://junglewise.ai/threats/cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code"}],"high":42,"name":"IBM AIX","rank":2,"slug":"aix","score":216,"vendor":{"name":"IBM","slug":"ibm"},"critical":12,"max_cvss":9.9,"max_epss":0.0103,"exploited":0,"vulnerabilities":72,"url":"https://junglewise.ai/threats/technologies/aix"},{"hub":true,"top":[{"cve":"CVE-2026-18835","cvss":9.9,"epss":0.0079,"slug":"cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability","title":"IBM AIX and PowerVM VIOS command injection vulnerability","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:17.43+00:00","url":"https://junglewise.ai/threats/cve-2026-18835-ibm-aix-and-powervm-vios-command-injection-vulnerability"},{"cve":"CVE-2026-17160","cvss":9.8,"epss":0.008,"slug":"cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation","title":"IBM AIX and PowerVM VIOS integer overflow in size computation","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.36+00:00","url":"https://junglewise.ai/threats/cve-2026-17160-ibm-aix-and-powervm-vios-integer-overflow-in-size-computation"},{"cve":"CVE-2026-17157","cvss":9.8,"epss":0.008,"slug":"cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code","title":"IBM AIX and PowerVM VIOS stack buffer overflow remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-20T22:17:14.013+00:00","url":"https://junglewise.ai/threats/cve-2026-17157-ibm-aix-and-powervm-vios-stack-buffer-overflow-remote-code"}],"high":42,"name":"IBM PowerVM VIOS","rank":3,"slug":"powervm-vios","score":216,"vendor":{"name":"IBM","slug":"ibm"},"critical":12,"max_cvss":9.9,"max_epss":0.0103,"exploited":0,"vulnerabilities":72,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"hub":true,"top":[{"cve":"CVE-2026-75874","cvss":10,"epss":0.0046,"slug":"cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape","title":"Mozilla Firefox Remote Settings Client sandbox escape","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape"},{"cve":"CVE-2026-74990","cvss":9.8,"epss":0.0072,"slug":"cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs","title":"Mozilla Thunderbird memory corruption in internally found bugs","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.93+00:00","url":"https://junglewise.ai/threats/cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs"},{"cve":"CVE-2026-74989","cvss":9.8,"epss":0.0057,"slug":"cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153","title":"Mozilla Thunderbird memory corruption in version 153","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.81+00:00","url":"https://junglewise.ai/threats/cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153"}],"high":25,"name":"Mozilla Thunderbird","rank":4,"slug":"thunderbird","score":177,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":15,"max_cvss":10,"max_epss":0.0072,"exploited":0,"vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/thunderbird"},{"hub":true,"top":[{"cve":"CVE-2026-75874","cvss":10,"epss":0.0046,"slug":"cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape","title":"Mozilla Firefox Remote Settings Client sandbox escape","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape"},{"cve":"CVE-2026-74990","cvss":9.8,"epss":0.0072,"slug":"cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs","title":"Mozilla Thunderbird memory corruption in internally found bugs","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.93+00:00","url":"https://junglewise.ai/threats/cve-2026-74990-mozilla-thunderbird-memory-corruption-in-internally-found-bugs"},{"cve":"CVE-2026-74989","cvss":9.8,"epss":0.0057,"slug":"cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153","title":"Mozilla Thunderbird memory corruption in version 153","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.81+00:00","url":"https://junglewise.ai/threats/cve-2026-74989-mozilla-thunderbird-memory-corruption-in-version-153"}],"high":25,"name":"Mozilla Firefox","rank":5,"slug":"firefox","score":172,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":14,"max_cvss":10,"max_epss":0.0072,"exploited":0,"vulnerabilities":52,"url":"https://junglewise.ai/threats/technologies/firefox"},{"hub":true,"top":[{"cve":"CVE-2026-75874","cvss":10,"epss":0.0046,"slug":"cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape","title":"Mozilla Firefox Remote Settings Client sandbox escape","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape"},{"cve":"CVE-2026-74985","cvss":9.8,"epss":0.0053,"slug":"cve-2026-74985-mozilla-firefox-privilege-escalation-in-enterprise-policies","title":"Mozilla Firefox privilege escalation in Enterprise Policies","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.317+00:00","url":"https://junglewise.ai/threats/cve-2026-74985-mozilla-firefox-privilege-escalation-in-enterprise-policies"},{"cve":"CVE-2026-74979","cvss":9.8,"epss":0.0053,"slug":"cve-2026-74979-mozilla-firefox-add-ons-manager-mitigation-bypass","title":"Mozilla Firefox Add-ons Manager mitigation bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:36.683+00:00","url":"https://junglewise.ai/threats/cve-2026-74979-mozilla-firefox-add-ons-manager-mitigation-bypass"}],"high":25,"name":"Mozilla Firefox ESR","rank":6,"slug":"firefox-esr","score":159,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":12,"max_cvss":10,"max_epss":0.0068,"exploited":0,"vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/firefox-esr"},{"hub":true,"top":[{"cve":"CVE-2026-71164","cvss":9.8,"epss":0.0051,"slug":"cve-2026-71164-oracle-helidon-remote-code-execution-in-imperative-web-server","title":"Oracle Helidon remote code execution in Imperative Web Server","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:17.703+00:00","url":"https://junglewise.ai/threats/cve-2026-71164-oracle-helidon-remote-code-execution-in-imperative-web-server"},{"cve":"CVE-2026-71152","cvss":9.8,"epss":0.0051,"slug":"cve-2026-71152-oracle-helidon-remote-code-execution","title":"Oracle Helidon remote code execution","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:16.28+00:00","url":"https://junglewise.ai/threats/cve-2026-71152-oracle-helidon-remote-code-execution"},{"cve":"CVE-2026-71167","cvss":9.4,"epss":0.0046,"slug":"cve-2026-71167-oracle-helidon-unauthenticated-data-access-and-denial-of-service","title":"Oracle Helidon unauthenticated data access and denial of service","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:18.05+00:00","url":"https://junglewise.ai/threats/cve-2026-71167-oracle-helidon-unauthenticated-data-access-and-denial-of-service"}],"high":19,"name":"Oracle Helidon","rank":7,"slug":"helidon","score":123,"vendor":{"name":"Oracle","slug":"oracle"},"critical":6,"max_cvss":9.8,"max_epss":0.0051,"exploited":0,"vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/helidon"},{"hub":true,"top":[{"cve":"CVE-2026-70880","cvss":10,"epss":0.0051,"slug":"cve-2026-70880-oracle-hyperion-data-relationship-management-authentication","title":"Oracle Hyperion Data Relationship Management authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:44.49+00:00","url":"https://junglewise.ai/threats/cve-2026-70880-oracle-hyperion-data-relationship-management-authentication"},{"cve":"CVE-2026-70873","cvss":9.8,"epss":0.0051,"slug":"cve-2026-70873-oracle-hyperion-data-relationship-management-authentication","title":"Oracle Hyperion Data Relationship Management authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:43.607+00:00","url":"https://junglewise.ai/threats/cve-2026-70873-oracle-hyperion-data-relationship-management-authentication"},{"cve":"CVE-2026-70871","cvss":9.8,"epss":0.0051,"slug":"cve-2026-70871-oracle-hyperion-data-relationship-management-authentication","title":"Oracle Hyperion Data Relationship Management authentication bypass in access control","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:43.36+00:00","url":"https://junglewise.ai/threats/cve-2026-70871-oracle-hyperion-data-relationship-management-authentication"}],"high":26,"name":"Oracle Hyperion Data Relationship Management","rank":8,"slug":"hyperion-data-relationship-management","score":122,"vendor":{"name":"Oracle","slug":"oracle"},"critical":7,"max_cvss":10,"max_epss":0.0051,"exploited":0,"vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/hyperion-data-relationship-management"},{"hub":true,"top":[{"cve":"CVE-2026-71037","cvss":9.3,"epss":0.0038,"slug":"cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http","title":"Oracle Commerce Guided Search remote code execution via HTTP","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.427+00:00","url":"https://junglewise.ai/threats/cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http"},{"cve":"CVE-2026-70998","cvss":9.3,"epss":0.0035,"slug":"cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access","title":"Oracle Commerce Guided Search remote unauthenticated data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:58.883+00:00","url":"https://junglewise.ai/threats/cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access"},{"cve":"CVE-2026-71036","cvss":9.1,"epss":0.0043,"slug":"cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access","title":"Oracle Commerce Experience Manager unauthorized data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.313+00:00","url":"https://junglewise.ai/threats/cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access"}],"high":21,"name":"Oracle Commerce Experience Manager","rank":9,"slug":"commerce-experience-manager","score":117,"vendor":{"name":"Oracle","slug":"oracle"},"critical":7,"max_cvss":9.3,"max_epss":0.0049,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/commerce-experience-manager"},{"hub":true,"top":[{"cve":"CVE-2026-71037","cvss":9.3,"epss":0.0038,"slug":"cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http","title":"Oracle Commerce Guided Search remote code execution via HTTP","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.427+00:00","url":"https://junglewise.ai/threats/cve-2026-71037-oracle-commerce-guided-search-remote-code-execution-via-http"},{"cve":"CVE-2026-70998","cvss":9.3,"epss":0.0035,"slug":"cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access","title":"Oracle Commerce Guided Search remote unauthenticated data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:58.883+00:00","url":"https://junglewise.ai/threats/cve-2026-70998-oracle-commerce-guided-search-remote-unauthenticated-data-access"},{"cve":"CVE-2026-71036","cvss":9.1,"epss":0.0043,"slug":"cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access","title":"Oracle Commerce Experience Manager unauthorized data access","severity":"critical","exploited":false,"published_at":"2026-08-18T21:18:03.313+00:00","url":"https://junglewise.ai/threats/cve-2026-71036-oracle-commerce-experience-manager-unauthorized-data-access"}],"high":21,"name":"Oracle Commerce Guided Search","rank":10,"slug":"commerce-guided-search","score":117,"vendor":{"name":"Oracle","slug":"oracle"},"critical":7,"max_cvss":9.3,"max_epss":0.0049,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/commerce-guided-search"},{"hub":true,"top":[{"cve":"CVE-2026-70921","cvss":10,"epss":0.0043,"slug":"cve-2026-70921-oracle-hyperion-financial-management-authentication-bypass-in-tls","title":"Oracle Hyperion Financial Management authentication bypass in TLS","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:49.927+00:00","url":"https://junglewise.ai/threats/cve-2026-70921-oracle-hyperion-financial-management-authentication-bypass-in-tls"},{"cve":"CVE-2026-70920","cvss":9.9,"epss":0.0043,"slug":"cve-2026-70920-oracle-hyperion-financial-management-sql-injection-vulnerability","title":"Oracle Hyperion Financial Management SQL injection vulnerability in Security component","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:49.81+00:00","url":"https://junglewise.ai/threats/cve-2026-70920-oracle-hyperion-financial-management-sql-injection-vulnerability"},{"cve":"CVE-2026-70854","cvss":9.1,"epss":0.0045,"slug":"cve-2026-70854-oracle-hyperion-financial-management-authentication-bypass-in","title":"Oracle Hyperion Financial Management authentication bypass in Security component","severity":"critical","exploited":false,"published_at":"2026-08-18T21:17:41.48+00:00","url":"https://junglewise.ai/threats/cve-2026-70854-oracle-hyperion-financial-management-authentication-bypass-in"}],"high":18,"name":"Oracle Hyperion Financial Management","rank":11,"slug":"hyperion-financial-management","score":100,"vendor":{"name":"Oracle","slug":"oracle"},"critical":3,"max_cvss":10,"max_epss":0.0049,"exploited":0,"vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/hyperion-financial-management"},{"hub":true,"top":[{"cve":"CVE-2026-72717","cvss":4,"epss":0.0065,"slug":"cve-2026-72717-orval-zod-schema-code-injection-via-unescaped-default-value","title":"Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expressi","severity":"critical","exploited":false,"published_at":"2026-08-19T18:17:25.203+00:00","url":"https://junglewise.ai/threats/cve-2026-72717-orval-zod-schema-code-injection-via-unescaped-default-value"},{"cve":"CVE-2026-72716","cvss":4,"epss":0.0065,"slug":"cve-2026-72716-orval-code-generation-rce-via-unescaped-template-literals-in-zod","title":"Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expressi","severity":"critical","exploited":false,"published_at":"2026-08-19T18:17:25.057+00:00","url":"https://junglewise.ai/threats/cve-2026-72716-orval-code-generation-rce-via-unescaped-template-literals-in-zod"},{"cve":"CVE-2026-71871","cvss":4,"epss":0.0065,"slug":"cve-2026-71871-orval-code-injection-in-zod-schema-generation","title":"Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expressi","severity":"critical","exploited":false,"published_at":"2026-08-19T18:17:24.68+00:00","url":"https://junglewise.ai/threats/cve-2026-71871-orval-code-injection-in-zod-schema-generation"}],"high":1,"name":"Npm Orval","rank":12,"slug":"orval","score":69,"vendor":{"name":"Npm","slug":"npm"},"critical":11,"max_cvss":7.1,"max_epss":0.0065,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/orval"},{"hub":true,"top":[{"cve":"CVE-2026-62440","cvss":9.1,"epss":0.0054,"slug":"cve-2026-62440-apache-cloudstack-improper-access-control-in-kubernetes-service","title":"Apache CloudStack improper access control in Kubernetes Service plugin","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:39.963+00:00","url":"https://junglewise.ai/threats/cve-2026-62440-apache-cloudstack-improper-access-control-in-kubernetes-service"},{"cve":"CVE-2026-61398","cvss":9.1,"epss":0.0057,"slug":"cve-2026-61398-apache-cloudstack-improper-output-encoding-in-password-reset-ui","title":"Apache CloudStack improper output encoding in password reset UI","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:39.48+00:00","url":"https://junglewise.ai/threats/cve-2026-61398-apache-cloudstack-improper-output-encoding-in-password-reset-ui"},{"cve":"CVE-2026-59085","cvss":9.1,"epss":0.0059,"slug":"cve-2026-59085-apache-cloudstack-ssrf-in-webhook-module","title":"Apache CloudStack SSRF in webhook module","severity":"critical","exploited":false,"published_at":"2026-08-21T09:16:38.41+00:00","url":"https://junglewise.ai/threats/cve-2026-59085-apache-cloudstack-ssrf-in-webhook-module"}],"high":12,"name":"Apache CloudStack","rank":13,"slug":"cloudstack","score":59,"vendor":{"name":"Apache","slug":"apache"},"critical":3,"max_cvss":9.1,"max_epss":0.0291,"exploited":0,"vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"hub":true,"top":[{"cve":"CVE-2026-48769","cvss":9.9,"epss":0.0073,"slug":"cve-2026-48769-lxc-incus-arbitrary-file-write-via-image-hash-path-traversal","title":"Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a m","severity":"critical","exploited":false,"published_at":"2026-08-21T15:16:41.347+00:00","url":"https://junglewise.ai/threats/cve-2026-48769-lxc-incus-arbitrary-file-write-via-image-hash-path-traversal"},{"cve":"CVE-2026-48755","cvss":9.9,"epss":0.0073,"slug":"cve-2026-48755-lxc-incus-argument-injection-in-backup-compression-algorithm","title":"Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression alg","severity":"critical","exploited":false,"published_at":"2026-08-21T15:16:41.077+00:00","url":"https://junglewise.ai/threats/cve-2026-48755-lxc-incus-argument-injection-in-backup-compression-algorithm"},{"cve":"CVE-2026-48753","cvss":9.9,"epss":0.0073,"slug":"cve-2026-48753-incus-arbitrary-file-write-via-path-traversal-in-s3-multipart","title":"Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path trave","severity":"critical","exploited":false,"published_at":"2026-08-21T15:16:40.8+00:00","url":"https://junglewise.ai/threats/cve-2026-48753-incus-arbitrary-file-write-via-path-traversal-in-s3-multipart"}],"high":1,"name":"Go Github.com/Lxc/Incus/V7/Cmd/Incusd","rank":14,"slug":"github-com-lxc-incus-v7-cmd-incusd","score":47,"vendor":{"name":"Go","slug":"go"},"critical":7,"max_cvss":9.9,"max_epss":0.0073,"exploited":0,"vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/github-com-lxc-incus-v7-cmd-incusd"},{"hub":true,"top":[{"cve":"CVE-2026-71513","cvss":8.8,"epss":0.011,"slug":"cve-2026-71513-nltk-allowlistunpickler-dotted-name-validation-bypass","title":"NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not","severity":"high","exploited":false,"published_at":"2026-08-22T14:16:33.417+00:00","url":"https://junglewise.ai/threats/cve-2026-71513-nltk-allowlistunpickler-dotted-name-validation-bypass"},{"cvss":7.5,"slug":"nltk-insecure-default-configuration-in-pathsec-f4930423","title":"NLTK insecure default configuration in pathsec","severity":"high","exploited":false,"published_at":"2026-08-22T15:31:03+00:00","url":"https://junglewise.ai/threats/nltk-insecure-default-configuration-in-pathsec-f4930423"},{"cvss":7.5,"slug":"nltk-unbounded-recursion-in-jsontaggeddecoder-decode-obj-e977609c","title":"NLTK unbounded recursion in JSONTaggedDecoder.decode_obj","severity":"high","exploited":false,"published_at":"2026-08-22T15:31:03+00:00","url":"https://junglewise.ai/threats/nltk-unbounded-recursion-in-jsontaggeddecoder-decode-obj-e977609c"}],"high":11,"name":"Pip Nltk","rank":15,"slug":"nltk","score":44,"vendor":{"name":"Pip","slug":"pip"},"critical":0,"max_cvss":8.8,"max_epss":0.011,"exploited":0,"vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/nltk"},{"hub":true,"top":[{"cve":"CVE-2026-33240","cvss":8.8,"epss":0.0047,"slug":"cve-2026-33240-combodo-itop-reflected-xss-in-foreign-key-search","title":"Combodo iTop reflected XSS in foreign key search","severity":"high","exploited":false,"published_at":"2026-08-21T22:16:36.863+00:00","url":"https://junglewise.ai/threats/cve-2026-33240-combodo-itop-reflected-xss-in-foreign-key-search"},{"cve":"CVE-2026-31936","cvss":8.8,"epss":0.0048,"slug":"cve-2026-31936-combodo-itop-unauthorized-access-via-search-operation","title":"Combodo iTop unauthorized access via search operation","severity":"high","exploited":false,"published_at":"2026-08-21T22:16:36.553+00:00","url":"https://junglewise.ai/threats/cve-2026-31936-combodo-itop-unauthorized-access-via-search-operation"},{"cve":"CVE-2026-34741","cvss":8.6,"epss":0.0064,"slug":"cve-2026-34741-combodo-itop-authentication-bypass-in-exec-php","title":"Combodo iTop authentication bypass in exec.php","severity":"high","exploited":false,"published_at":"2026-08-21T22:16:37.143+00:00","url":"https://junglewise.ai/threats/cve-2026-34741-combodo-itop-authentication-bypass-in-exec-php"}],"high":13,"name":"Combodo iTop","rank":16,"slug":"itop","score":44,"vendor":{"name":"Combodo","slug":"combodo"},"critical":0,"max_cvss":8.8,"max_epss":0.0064,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/itop"},{"hub":true,"top":[{"cve":"CVE-2026-75874","cvss":10,"epss":0.0046,"slug":"cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape","title":"Mozilla Firefox Remote Settings Client sandbox escape","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-75874-mozilla-firefox-remote-settings-client-sandbox-escape"},{"cve":"CVE-2026-74988","cvss":9.8,"epss":0.0061,"slug":"cve-2026-74988-mozilla-thunderbird-memory-corruption-in-esr-153-0-and-153","title":"Mozilla Thunderbird memory corruption in ESR 153.0 and 153","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.687+00:00","url":"https://junglewise.ai/threats/cve-2026-74988-mozilla-thunderbird-memory-corruption-in-esr-153-0-and-153"},{"cve":"CVE-2026-74985","cvss":9.8,"epss":0.0053,"slug":"cve-2026-74985-mozilla-firefox-privilege-escalation-in-enterprise-policies","title":"Mozilla Firefox privilege escalation in Enterprise Policies","severity":"critical","exploited":false,"published_at":"2026-08-18T13:17:40.317+00:00","url":"https://junglewise.ai/threats/cve-2026-74985-mozilla-firefox-privilege-escalation-in-enterprise-policies"}],"high":6,"name":"Mozilla Thunderbird-Esr","rank":17,"slug":"thunderbird-esr","score":44,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":4,"max_cvss":10,"max_epss":0.0068,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/thunderbird-esr"},{"hub":true,"top":[{"cve":"CVE-2026-77071","cvss":9.8,"epss":0.0062,"slug":"cve-2026-77071-n8n-supabase-node-postgrest-filter-injection-in-row-operations","title":"n8n Supabase node PostgREST filter injection in Row operations","severity":"critical","exploited":false,"published_at":"2026-08-20T12:16:38.353+00:00","url":"https://junglewise.ai/threats/cve-2026-77071-n8n-supabase-node-postgrest-filter-injection-in-row-operations"},{"cve":"CVE-2026-77070","cvss":9.8,"epss":0.0051,"slug":"cve-2026-77070-n8n-mongodb-node-nosql-injection-in-query-operations","title":"n8n MongoDB node NoSQL injection in query operations","severity":"critical","exploited":false,"published_at":"2026-08-20T12:16:38.227+00:00","url":"https://junglewise.ai/threats/cve-2026-77070-n8n-mongodb-node-nosql-injection-in-query-operations"},{"cve":"CVE-2026-77084","cvss":8.8,"epss":0.0069,"slug":"cve-2026-77084-n8n-git-node-os-command-injection-via-unchecked-configuration","title":"n8n Git node OS command injection via unchecked configuration","severity":"high","exploited":false,"published_at":"2026-08-20T12:16:39.97+00:00","url":"https://junglewise.ai/threats/cve-2026-77084-n8n-git-node-os-command-injection-via-unchecked-configuration"}],"high":8,"name":"N8n","rank":18,"slug":"n8n","score":43,"vendor":{"name":"N8n","slug":"n8n"},"critical":2,"max_cvss":9.8,"max_epss":0.0093,"exploited":0,"vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/n8n"},{"hub":true,"top":[{"cve":"CVE-2026-75851","cvss":9.9,"epss":0.0044,"slug":"cve-2026-75851-arcadedb-server-privilege-escalation-in-async-command-execution","title":"ArcadeDB server privilege escalation in async command execution","severity":"critical","exploited":false,"published_at":"2026-08-18T12:19:35.457+00:00","url":"https://junglewise.ai/threats/cve-2026-75851-arcadedb-server-privilege-escalation-in-async-command-execution"},{"cve":"CVE-2026-75843","cvss":9.9,"epss":0.0044,"slug":"cve-2026-75843-arcadedb-grpc-transaction-privilege-escalation-via-authentication","title":"ArcadeDB gRPC transaction privilege escalation via authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T12:19:34.74+00:00","url":"https://junglewise.ai/threats/cve-2026-75843-arcadedb-grpc-transaction-privilege-escalation-via-authentication"},{"cve":"CVE-2026-75854","cvss":9.8,"epss":0.0089,"slug":"cve-2026-75854-arcadedb-redis-wire-protocol-plugin-authentication-bypass","title":"ArcadeDB Redis wire-protocol plugin authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-18T12:19:35.86+00:00","url":"https://junglewise.ai/threats/cve-2026-75854-arcadedb-redis-wire-protocol-plugin-authentication-bypass"}],"high":5,"name":"ArcadeData ArcadeDB","rank":19,"slug":"arcadedb","score":43,"vendor":{"name":"ArcadeData","slug":"arcadedata"},"critical":4,"max_cvss":9.9,"max_epss":0.0089,"exploited":0,"vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/arcadedb"},{"hub":true,"top":[{"cve":"CVE-2026-16835","cvss":9.6,"epss":0.0036,"slug":"cve-2026-16835-ibm-power-systems-firmware-authentication-bypass-in-fsp","title":"IBM Power Systems firmware authentication bypass in FSP management protocol","severity":"critical","exploited":false,"published_at":"2026-08-19T19:17:10.69+00:00","url":"https://junglewise.ai/threats/cve-2026-16835-ibm-power-systems-firmware-authentication-bypass-in-fsp"},{"cve":"CVE-2026-16687","cvss":9.6,"epss":0.0035,"slug":"cve-2026-16687-ibm-power-systems-firmware-stack-buffer-overflow-in-asmi-web","title":"IBM Power Systems Firmware stack buffer overflow in ASMI web interface","severity":"critical","exploited":false,"published_at":"2026-08-19T19:17:10.28+00:00","url":"https://junglewise.ai/threats/cve-2026-16687-ibm-power-systems-firmware-stack-buffer-overflow-in-asmi-web"},{"cve":"CVE-2026-16832","cvss":8.4,"epss":0.0032,"slug":"cve-2026-16832-ibm-power-systems-firmware-stack-based-buffer-overflow-in-fsp","title":"IBM Power Systems Firmware stack-based buffer overflow in FSP management protocol","severity":"high","exploited":false,"published_at":"2026-08-19T19:17:10.557+00:00","url":"https://junglewise.ai/threats/cve-2026-16832-ibm-power-systems-firmware-stack-based-buffer-overflow-in-fsp"}],"high":9,"name":"IBM Power Systems Firmware","rank":20,"slug":"power-systems-firmware","score":40,"vendor":{"name":"IBM","slug":"ibm"},"critical":2,"max_cvss":9.6,"max_epss":0.0036,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/power-systems-firmware"},{"hub":true,"top":[{"cve":"CVE-2026-65346","cvss":8.8,"epss":0.0059,"slug":"cve-2026-65346-apple-imageio-integer-overflow-in-image-processing","title":"Apple ImageIO integer overflow in image processing","severity":"high","exploited":false,"published_at":"2026-08-17T22:17:25.293+00:00","url":"https://junglewise.ai/threats/cve-2026-65346-apple-imageio-integer-overflow-in-image-processing"},{"cve":"CVE-2026-43794","cvss":8.8,"epss":0.0042,"slug":"cve-2026-43794-apple-webkit-memory-corruption-in-web-content-processing","title":"Apple WebKit memory corruption in web content processing","severity":"high","exploited":false,"published_at":"2026-08-17T22:17:11.457+00:00","url":"https://junglewise.ai/threats/cve-2026-43794-apple-webkit-memory-corruption-in-web-content-processing"},{"cve":"CVE-2026-19875","cvss":7.5,"epss":0.0052,"slug":"cve-2026-19875-ibm-langflow-oss-authentication-bypass-in-registration-endpoint","title":"IBM Langflow OSS authentication bypass in registration endpoint","severity":"high","exploited":false,"published_at":"2026-08-19T18:16:36.557+00:00","url":"https://junglewise.ai/threats/cve-2026-19875-ibm-langflow-oss-authentication-bypass-in-registration-endpoint"}],"high":4,"name":"Apple macOS","rank":21,"slug":"macos-tahoe","score":39,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":8.8,"max_epss":0.0069,"exploited":0,"vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-71131","cvss":8.6,"epss":0.0018,"slug":"cve-2026-71131-oracle-vm-virtualbox-privilege-escalation-in-core","title":"Oracle VM VirtualBox privilege escalation in Core","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:13.967+00:00","url":"https://junglewise.ai/threats/cve-2026-71131-oracle-vm-virtualbox-privilege-escalation-in-core"},{"cve":"CVE-2026-71130","cvss":8.2,"epss":0.0035,"slug":"cve-2026-71130-oracle-vm-virtualbox-rdp-remote-access-vulnerability-in-core","title":"Oracle VM VirtualBox RDP remote access vulnerability in Core","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:13.853+00:00","url":"https://junglewise.ai/threats/cve-2026-71130-oracle-vm-virtualbox-rdp-remote-access-vulnerability-in-core"},{"cve":"CVE-2026-71129","cvss":8.2,"epss":0.0018,"slug":"cve-2026-71129-oracle-vm-virtualbox-privilege-escalation-in-core","title":"Oracle VM VirtualBox privilege escalation in Core","severity":"high","exploited":false,"published_at":"2026-08-18T21:18:13.737+00:00","url":"https://junglewise.ai/threats/cve-2026-71129-oracle-vm-virtualbox-privilege-escalation-in-core"}],"high":9,"name":"Oracle VirtualBox","rank":22,"slug":"virtualbox","score":39,"vendor":{"name":"Oracle","slug":"oracle"},"critical":0,"max_cvss":8.6,"max_epss":0.0044,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/virtualbox"},{"hub":true,"top":[{"cve":"CVE-2026-65346","cvss":8.8,"epss":0.0059,"slug":"cve-2026-65346-apple-imageio-integer-overflow-in-image-processing","title":"Apple ImageIO integer overflow in image processing","severity":"high","exploited":false,"published_at":"2026-08-17T22:17:25.293+00:00","url":"https://junglewise.ai/threats/cve-2026-65346-apple-imageio-integer-overflow-in-image-processing"},{"cve":"CVE-2026-43794","cvss":8.8,"epss":0.0042,"slug":"cve-2026-43794-apple-webkit-memory-corruption-in-web-content-processing","title":"Apple WebKit memory corruption in web content processing","severity":"high","exploited":false,"published_at":"2026-08-17T22:17:11.457+00:00","url":"https://junglewise.ai/threats/cve-2026-43794-apple-webkit-memory-corruption-in-web-content-processing"},{"cve":"CVE-2026-65343","cvss":7.5,"epss":0.0069,"slug":"cve-2026-65343-apple-ios-and-ipados-kernel-use-after-free-memory-corruption","title":"Apple iOS and iPadOS kernel use-after-free memory corruption","severity":"high","exploited":false,"published_at":"2026-08-17T22:17:25.2+00:00","url":"https://junglewise.ai/threats/cve-2026-65343-apple-ios-and-ipados-kernel-use-after-free-memory-corruption"}],"high":3,"name":"Apple iPadOS","rank":23,"slug":"ipados","score":36,"vendor":{"name":"Apple","slug":"apple"},"critical":0,"max_cvss":8.8,"max_epss":0.0069,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/ipados"},{"hub":true,"top":[{"cve":"CVE-2026-71513","cvss":8.8,"epss":0.011,"slug":"cve-2026-71513-nltk-allowlistunpickler-dotted-name-validation-bypass","title":"NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not","severity":"high","exploited":false,"published_at":"2026-08-22T14:16:33.417+00:00","url":"https://junglewise.ai/threats/cve-2026-71513-nltk-allowlistunpickler-dotted-name-validation-bypass"},{"cvss":7.5,"slug":"nltk-unbounded-recursion-in-jsontaggeddecoder-decode-obj-e977609c","title":"NLTK unbounded recursion in JSONTaggedDecoder.decode_obj","severity":"high","exploited":false,"published_at":"2026-08-22T15:31:03+00:00","url":"https://junglewise.ai/threats/nltk-unbounded-recursion-in-jsontaggeddecoder-decode-obj-e977609c"},{"cvss":7.5,"slug":"nltk-insecure-default-configuration-in-pathsec-f4930423","title":"NLTK insecure default configuration in pathsec","severity":"high","exploited":false,"published_at":"2026-08-22T15:31:03+00:00","url":"https://junglewise.ai/threats/nltk-insecure-default-configuration-in-pathsec-f4930423"}],"high":8,"name":"NLTK Project Natural Language Toolkit","rank":24,"slug":"natural-language-toolkit","score":35,"vendor":{"name":"NLTK Project","slug":"nltk-project"},"critical":0,"max_cvss":8.8,"max_epss":0.011,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/natural-language-toolkit"},{"hub":true,"top":[{"cve":"CVE-2026-8445","cvss":9.8,"epss":0.0064,"slug":"cve-2026-8445-justhtml-html-escaping-bypass-in-markdown-conversion","title":"justhtml HTML escaping bypass in Markdown conversion","severity":"critical","exploited":false,"published_at":"2026-08-23T14:16:54.957+00:00","url":"https://junglewise.ai/threats/cve-2026-8445-justhtml-html-escaping-bypass-in-markdown-conversion"},{"cve":"CVE-2026-7808","cvss":9.8,"epss":0.0059,"slug":"cve-2026-7808-justhtml-html-sanitization-bypass-leading-to-xss","title":"justhtml HTML sanitization bypass leading to XSS","severity":"critical","exploited":false,"published_at":"2026-08-23T14:16:54.81+00:00","url":"https://junglewise.ai/threats/cve-2026-7808-justhtml-html-sanitization-bypass-leading-to-xss"},{"cve":"CVE-2026-5388","cvss":9.8,"epss":0.0059,"slug":"cve-2026-5388-justhtml-multiple-security-issues-in-url-sanitization-and-html","title":"justhtml multiple security issues in URL sanitization and HTML serialization","severity":"critical","exploited":false,"published_at":"2026-08-23T14:16:53.47+00:00","url":"https://junglewise.ai/threats/cve-2026-5388-justhtml-multiple-security-issues-in-url-sanitization-and-html"}],"high":3,"name":"Pip Justhtml","rank":25,"slug":"justhtml","score":33,"vendor":{"name":"Pip","slug":"pip"},"critical":3,"max_cvss":9.8,"max_epss":0.0065,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/justhtml"}],"previous":{"key":"2026-08-10","top":"Linux Kernel","period":{"end":"2026-08-16","start":"2026-08-10"},"totals":{"high":789,"critical":222,"exploited":6,"technologies":951,"vulnerabilities":1900},"url":"https://junglewise.ai/threats/weekly/2026-08-10"},"next":{"key":"2026-08-24","top":"Google Chrome","period":{"end":"2026-08-30","start":"2026-08-24"},"totals":{"high":968,"critical":331,"exploited":10,"technologies":1154,"vulnerabilities":2819},"url":"https://junglewise.ai/threats/weekly/2026-08-24"}}