Weekly report
Most vulnerable technologies: week of 24 to 30 August 2026 (week 35)
Final report, published . It does not change.
In the week of 24 to 30 August 2026, Junglewise Threat Intelligence recorded 2,819 new vulnerabilities: 331 critical, 968 high and 10 exploited in the wild. The most vulnerable technology was Google Chrome, with 327 vulnerabilities (44 critical), followed by Linux Kernel (249) and Pip Nltk (33).
- New vulnerabilities
- 2,819
- Critical
- 331
- Exploited in the wild
- 10
- Technologies affected
- 1,154
Ranking
Most affected vendors
- 1.Google333 vulnerabilities, 44 critical, 0 exploited
- 2.Linux249 vulnerabilities, 41 critical, 1 exploited
- 3.Pip51 vulnerabilities, 10 critical, 0 exploited
- 4.Ubiquiti22 vulnerabilities, 22 critical, 0 exploited
- 5.DrayTek40 vulnerabilities, 3 critical, 0 exploited
- 6.Adobe41 vulnerabilities, 3 critical, 0 exploited
- 7.Microsoft35 vulnerabilities, 7 critical, 1 exploited
- 8.Go37 vulnerabilities, 5 critical, 1 exploited
- 9.Jahlives34 vulnerabilities, 4 critical, 0 exploited
- 10.Apache24 vulnerabilities, 7 critical, 0 exploited
Most severe vulnerabilities
- CVE-2021-23758: Ajax.NET Professional unsafe deserialization of untrusted datacriticalexploited in the wildCVSS 9.8EPSS 82.6%
- CVE-2026-60004: Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.criticalexploited in the wildCVSS 9.8EPSS 24.0%
- CVE-2026-82329: JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated…criticalexploited in the wildCVSS 9.8EPSS 14.1%
- CVE-2026-81578: An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under…criticalexploited in the wildCVSS 9.8EPSS 4.5%
- CVE-2026-82078: An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG…criticalexploited in the wildCVSS 9.1EPSS 3.8%
- CVE-2015-5287: Red Hat ABRT privilege escalation via symlink attackcriticalexploited in the wildCVSS 7EPSS 5.0%
- CVE-2019-1068: Microsoft SQL Server remote code executioncriticalexploited in the wildEPSS 57.9%
- CVE-2023-49105: ownCloud improper authentication vulnerabilitycriticalexploited in the wildEPSS 42.9%
- CVE-2015-3246: Red Hat Libuser race condition in passwd file handlingcriticalexploited in the wildEPSS 8.8%
- CVE-2022-0995: Linux Kernel out-of-bounds write vulnerabilitycriticalexploited in the wildEPSS 8.8%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-08-24.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 24 to 30 August 2026 (week 35)", https://junglewise.ai/threats/weekly/2026-08-24, 26 September 2026.