Weekly report
Most vulnerable technologies: week of 31 August to 6 September 2026 (week 36)
Final report, published . It does not change.
In the week of 31 August to 6 September 2026, Junglewise Threat Intelligence recorded 2,379 new vulnerabilities: 294 critical, 771 high and 7 exploited in the wild. The most vulnerable technology was Linux Kernel, with 204 vulnerabilities (1 critical), followed by Google Chrome (37) and Arubanetworks Fabric Composer (51).
- New vulnerabilities
- 2,379
- Critical
- 294
- Exploited in the wild
- 7
- Technologies affected
- 1,040
Ranking
Most affected vendors
- 1.Linux204 vulnerabilities, 1 critical, 0 exploited
- 2.Go53 vulnerabilities, 7 critical, 0 exploited
- 3.Google41 vulnerabilities, 11 critical, 1 exploited
- 4.Hpe53 vulnerabilities, 5 critical, 0 exploited
- 5.Npm58 vulnerabilities, 5 critical, 0 exploited
- 6.Arubanetworks51 vulnerabilities, 5 critical, 0 exploited
- 7.IBM70 vulnerabilities, 2 critical, 0 exploited
- 8.Mozilla34 vulnerabilities, 11 critical, 0 exploited
- 9.SiYuan40 vulnerabilities, 4 critical, 0 exploited
- 10.Nvidia30 vulnerabilities, 0 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-83548: A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended…criticalexploited in the wildCVSS 10EPSS 8.8%
- CVE-2026-86218: N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.criticalexploited in the wildCVSS 9.8EPSS 12.9%
- CVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited…criticalexploited in the wildCVSS 9.8EPSS 1.8%
- CVE-2026-85046: Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside…criticalexploited in the wildCVSS 8.8EPSS 48.9%
- CVE-2026-67277: RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An…criticalexploited in the wildCVSS 8.2EPSS 1.6%
- CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…criticalexploited in the wildCVSS 7.8EPSS 10.8%
- CVE-2026-67279: RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never…criticalexploited in the wildCVSS 6.5EPSS 0.7%
- CVE-2026-82971: QVidium Opera11 command injection in net_tr.cgicriticalCVSS 10EPSS 3.3%
- CVE-2026-86152: Tenda CP3 OS command injection in AutoAddWificriticalCVSS 10EPSS 2.9%
- CVE-2026-69084: SiYuan arbitrary SQL execution via searchEmbedBlockcriticalCVSS 10EPSS 1.6%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-08-31.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 31 August to 6 September 2026 (week 36)", https://junglewise.ai/threats/weekly/2026-08-31, 26 September 2026.