Junglewise

Weekly report

Most vulnerable technologies: week of 31 August to 6 September 2026 (week 36)

Final report, published . It does not change.

In the week of 31 August to 6 September 2026, Junglewise Threat Intelligence recorded 2,379 new vulnerabilities: 294 critical, 771 high and 7 exploited in the wild. The most vulnerable technology was Linux Kernel, with 204 vulnerabilities (1 critical), followed by Google Chrome (37) and Arubanetworks Fabric Composer (51).

New vulnerabilities
2,379
Critical
294
Exploited in the wild
7
Technologies affected
1,040

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Linux Kernel
Linux
20412209.3
2Google Chrome
Google
37111219.8
3Arubanetworks Fabric Composer
Arubanetworks
51523010
4Hpe Networking Fabric Composer
Hpe
51523010
5SiYuan
SiYuan
43419010
6Mozilla Thunderbird
Mozilla
30101009.8
7Nvidia Megatron-Bridge
Nvidia
3003007.8
8Nvidia NeMo Megatron Bridge
Nvidia
3003007.8
9Mozilla Firefox
Mozilla
248609.8
10Go Github.com/Siyuan-Note/Siyuan/Kernel
Go
30314010
11WWBN AVideo
WWBN
2751009.8
12Mozilla Firefox ESR
Mozilla
197409.8
13MikroTik RouterOS
MikroTik
33039.8
14D-Link DNS-340L
D-Link
77009.9
15Npm @Xmldom/Xmldom
Npm
1501304
16MOOS Core-Moos
MOOS
123709.8
17Elastic Kibana
Elastic
300508.3
18Dell PowerStore
Dell
1311109.8
19Microsoft Windows
Microsoft
200808.8
20YesWiki
YesWiki
122609.4
21Composer Yeswiki/Yeswiki
Composer
122609.4
22Mozilla Thunderbird-Esr
Mozilla
113409.8
23Haxx Curl
Haxx
92709.8
24Sitecore CMS
Sitecore
151609.8
25SonicWall SMA1000
SonicWall
220210

Most affected vendors

  1. 1.Linux204 vulnerabilities, 1 critical, 0 exploited
  2. 2.Go53 vulnerabilities, 7 critical, 0 exploited
  3. 3.Google41 vulnerabilities, 11 critical, 1 exploited
  4. 4.Hpe53 vulnerabilities, 5 critical, 0 exploited
  5. 5.Npm58 vulnerabilities, 5 critical, 0 exploited
  6. 6.Arubanetworks51 vulnerabilities, 5 critical, 0 exploited
  7. 7.IBM70 vulnerabilities, 2 critical, 0 exploited
  8. 8.Mozilla34 vulnerabilities, 11 critical, 0 exploited
  9. 9.SiYuan40 vulnerabilities, 4 critical, 0 exploited
  10. 10.Nvidia30 vulnerabilities, 0 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/weekly/2026-08-31.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 31 August to 6 September 2026 (week 36)", https://junglewise.ai/threats/weekly/2026-08-31, 26 September 2026.