{"schema_version":1,"title":"Most vulnerable technologies: week of 31 August to 6 September 2026 (week 36)","summary":"In the week of 31 August to 6 September 2026, Junglewise Threat Intelligence recorded 2,379 new vulnerabilities: 294 critical, 771 high and 7 exploited in the wild. The most vulnerable technology was Linux Kernel, with 204 vulnerabilities (1 critical), followed by Google Chrome (37) and Arubanetworks Fabric Composer (51).","url":"https://junglewise.ai/threats/weekly/2026-08-31","json_url":"https://junglewise.ai/threats/weekly/2026-08-31.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/weekly/2026-08-31","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"week","period":{"end":"2026-09-06","start":"2026-08-31"},"totals":{"high":771,"critical":294,"exploited":7,"technologies":1040,"vulnerabilities":2379},"notable":[{"cve":"CVE-2026-83548","cvss":10,"epss":0.0876,"slug":"cve-2026-83548-sonicwall-sma1000-server-side-request-forgery","title":"A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A r","severity":"critical","exploited":true,"published_at":"2026-09-01T22:17:13.17+00:00","url":"https://junglewise.ai/threats/cve-2026-83548-sonicwall-sma1000-server-side-request-forgery"},{"cve":"CVE-2026-86218","cvss":9.8,"epss":0.1293,"slug":"cve-2026-86218-n-able-n-central-static-code-injection-vulnerability","title":"N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.","severity":"critical","exploited":true,"published_at":"2026-09-06T03:17:17.373+00:00","url":"https://junglewise.ai/threats/cve-2026-86218-n-able-n-central-static-code-injection-vulnerability"},{"cve":"CVE-2026-86060","cvss":9.8,"epss":0.0185,"slug":"cve-2026-86060-mikrotik-routeros-argument-delimiter-neutralization-privilege","title":"RouterOS contains an argument-handling flaw in the SSH login\npath involving usernames that begin with a prohibited character, allowing for t","severity":"critical","exploited":true,"published_at":"2026-09-05T20:17:18.703+00:00","url":"https://junglewise.ai/threats/cve-2026-86060-mikrotik-routeros-argument-delimiter-neutralization-privilege"},{"cve":"CVE-2026-85046","cvss":8.8,"epss":0.4888,"slug":"cve-2026-85046-google-chromium-v8-type-confusion-vulnerability","title":"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr","severity":"critical","exploited":true,"published_at":"2026-09-03T20:17:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-85046-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2026-67277","cvss":8.2,"epss":0.0156,"slug":"cve-2026-67277-mikrotik-routeros-missing-authentication-in-btest-service","title":"RouterOS accepts a \"related\" btest connection before the corresponding primary session has completed authentication. An unauthenticated clie","severity":"critical","exploited":true,"published_at":"2026-09-05T20:17:18.12+00:00","url":"https://junglewise.ai/threats/cve-2026-67277-mikrotik-routeros-missing-authentication-in-btest-service"},{"cve":"CVE-2026-83549","cvss":7.8,"epss":0.1076,"slug":"cve-2026-83549-sonicwall-sma1000-os-command-injection","title":"Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identi","severity":"critical","exploited":true,"published_at":"2026-09-01T22:17:13.29+00:00","url":"https://junglewise.ai/threats/cve-2026-83549-sonicwall-sma1000-os-command-injection"},{"cve":"CVE-2026-67279","cvss":6.5,"epss":0.0071,"slug":"cve-2026-67279-mikrotik-routeros-improper-behavioral-workflow-enforcement","title":"RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an","severity":"critical","exploited":true,"published_at":"2026-09-05T20:17:18.39+00:00","url":"https://junglewise.ai/threats/cve-2026-67279-mikrotik-routeros-improper-behavioral-workflow-enforcement"},{"cve":"CVE-2026-82971","cvss":10,"epss":0.0325,"slug":"cve-2026-82971-qvidium-opera11-command-injection-in-net-tr-cgi","title":"QVidium Opera11 command injection in net_tr.cgi","severity":"critical","exploited":false,"published_at":"2026-08-31T23:16:35.46+00:00","url":"https://junglewise.ai/threats/cve-2026-82971-qvidium-opera11-command-injection-in-net-tr-cgi"},{"cve":"CVE-2026-86152","cvss":10,"epss":0.0288,"slug":"cve-2026-86152-tenda-cp3-os-command-injection-in-autoaddwifi","title":"Tenda CP3 OS command injection in AutoAddWifi","severity":"critical","exploited":false,"published_at":"2026-09-06T02:17:19.37+00:00","url":"https://junglewise.ai/threats/cve-2026-86152-tenda-cp3-os-command-injection-in-autoaddwifi"},{"cve":"CVE-2026-69084","cvss":10,"epss":0.0157,"slug":"cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock","title":"SiYuan arbitrary SQL execution via searchEmbedBlock","severity":"critical","exploited":false,"published_at":"2026-09-03T20:19:22+00:00","url":"https://junglewise.ai/threats/cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock"}],"vendors":[{"hub":true,"high":22,"name":"Linux","rank":1,"slug":"linux","critical":1,"exploited":0,"vulnerabilities":204,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":25,"name":"Go","rank":2,"slug":"go","critical":7,"exploited":0,"vulnerabilities":53,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":13,"name":"Google","rank":3,"slug":"google","critical":11,"exploited":1,"vulnerabilities":41,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":24,"name":"Hpe","rank":4,"slug":"hpe","critical":5,"exploited":0,"vulnerabilities":53,"url":"https://junglewise.ai/threats/vendors/hpe"},{"hub":true,"high":20,"name":"Npm","rank":5,"slug":"npm","critical":5,"exploited":0,"vulnerabilities":58,"url":"https://junglewise.ai/threats/vendors/npm"},{"hub":true,"high":23,"name":"Arubanetworks","rank":6,"slug":"arubanetworks","critical":5,"exploited":0,"vulnerabilities":51,"url":"https://junglewise.ai/threats/vendors/arubanetworks"},{"hub":true,"high":16,"name":"IBM","rank":7,"slug":"ibm","critical":2,"exploited":0,"vulnerabilities":70,"url":"https://junglewise.ai/threats/vendors/ibm"},{"hub":true,"high":11,"name":"Mozilla","rank":8,"slug":"mozilla","critical":11,"exploited":0,"vulnerabilities":34,"url":"https://junglewise.ai/threats/vendors/mozilla"},{"hub":true,"high":16,"name":"SiYuan","rank":9,"slug":"siyuan","critical":4,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/vendors/siyuan"},{"hub":true,"high":30,"name":"Nvidia","rank":10,"slug":"nvidia","critical":0,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/vendors/nvidia"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-80726","cvss":9.3,"epss":0.0019,"slug":"cve-2026-80726-linux-kernel-kvm-x86-mmu-use-after-free-in-shadow-page-handling","title":"Linux kernel KVM x86 MMU use-after-free in shadow page handling","severity":"critical","exploited":false,"published_at":"2026-09-03T13:06:11.02+00:00","url":"https://junglewise.ai/threats/cve-2026-80726-linux-kernel-kvm-x86-mmu-use-after-free-in-shadow-page-handling"},{"cve":"CVE-2026-19298","cvss":8.8,"epss":0.005,"slug":"cve-2026-19298-ibm-langflow-oss-authorization-bypass-in-flow-build-endpoint","title":"IBM Langflow OSS authorization bypass in flow-build endpoint","severity":"high","exploited":false,"published_at":"2026-09-04T16:17:21.9+00:00","url":"https://junglewise.ai/threats/cve-2026-19298-ibm-langflow-oss-authorization-bypass-in-flow-build-endpoint"},{"cve":"CVE-2026-19305","cvss":8.6,"epss":0.0029,"slug":"cve-2026-19305-ibm-langflow-oss-server-side-request-forgery-in-url-validation","title":"IBM Langflow OSS server-side request forgery in URL validation","severity":"high","exploited":false,"published_at":"2026-09-04T16:17:24.323+00:00","url":"https://junglewise.ai/threats/cve-2026-19305-ibm-langflow-oss-server-side-request-forgery-in-url-validation"}],"high":22,"name":"Linux Kernel","rank":1,"slug":"kernel","score":253,"vendor":{"name":"Linux","slug":"linux"},"critical":1,"max_cvss":9.3,"max_epss":0.005,"exploited":0,"vulnerabilities":204,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-85046","cvss":8.8,"epss":0.4888,"slug":"cve-2026-85046-google-chromium-v8-type-confusion-vulnerability","title":"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr","severity":"critical","exploited":true,"published_at":"2026-09-03T20:17:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-85046-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2026-84325","cvss":9.8,"epss":0.004,"slug":"cve-2026-84325-google-chrome-improper-input-validation-in-datatransfer","title":"Google Chrome improper input validation in DataTransfer","severity":"critical","exploited":false,"published_at":"2026-09-02T00:18:27.34+00:00","url":"https://junglewise.ai/threats/cve-2026-84325-google-chrome-improper-input-validation-in-datatransfer"},{"cve":"CVE-2026-85050","cvss":9.6,"epss":0.0046,"slug":"cve-2026-85050-google-chrome-out-of-bounds-write-in-webgl","title":"Google Chrome out of bounds write in WebGL","severity":"critical","exploited":false,"published_at":"2026-09-03T20:17:26.077+00:00","url":"https://junglewise.ai/threats/cve-2026-85050-google-chrome-out-of-bounds-write-in-webgl"}],"high":12,"name":"Google Chrome","rank":2,"slug":"chrome","score":126,"vendor":{"name":"Google","slug":"google"},"critical":11,"max_cvss":9.8,"max_epss":0.4888,"exploited":1,"vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-76658","cvss":10,"epss":0.0075,"slug":"cve-2026-76658-hpe-networking-fabric-composer-ssh-daemon-auth-bypass","title":"HPE Networking Fabric Composer SSH daemon auth bypass","severity":"critical","exploited":false,"published_at":"2026-09-01T20:17:23.097+00:00","url":"https://junglewise.ai/threats/cve-2026-76658-hpe-networking-fabric-composer-ssh-daemon-auth-bypass"},{"cve":"CVE-2026-76657","cvss":10,"epss":0.0075,"slug":"cve-2026-76657-hpe-networking-fabric-composer-api-authentication-bypass","title":"HPE Networking Fabric Composer API authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-01T20:17:22.99+00:00","url":"https://junglewise.ai/threats/cve-2026-76657-hpe-networking-fabric-composer-api-authentication-bypass"},{"cve":"CVE-2026-19766","cvss":9.6,"epss":0.0026,"slug":"cve-2026-19766-hpe-networking-fabric-composer-authentication-bypass-in-os","title":"HPE Networking Fabric Composer authentication bypass in OS","severity":"critical","exploited":false,"published_at":"2026-09-01T20:17:12.76+00:00","url":"https://junglewise.ai/threats/cve-2026-19766-hpe-networking-fabric-composer-authentication-bypass-in-os"}],"high":23,"name":"Arubanetworks Fabric Composer","rank":3,"slug":"fabric-composer","score":122,"vendor":{"name":"Arubanetworks","slug":"arubanetworks"},"critical":5,"max_cvss":10,"max_epss":0.0145,"exploited":0,"vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/fabric-composer"},{"hub":true,"top":[{"cve":"CVE-2026-76658","cvss":10,"epss":0.0075,"slug":"cve-2026-76658-hpe-networking-fabric-composer-ssh-daemon-auth-bypass","title":"HPE Networking Fabric Composer SSH daemon auth bypass","severity":"critical","exploited":false,"published_at":"2026-09-01T20:17:23.097+00:00","url":"https://junglewise.ai/threats/cve-2026-76658-hpe-networking-fabric-composer-ssh-daemon-auth-bypass"},{"cve":"CVE-2026-76657","cvss":10,"epss":0.0075,"slug":"cve-2026-76657-hpe-networking-fabric-composer-api-authentication-bypass","title":"HPE Networking Fabric Composer API authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-01T20:17:22.99+00:00","url":"https://junglewise.ai/threats/cve-2026-76657-hpe-networking-fabric-composer-api-authentication-bypass"},{"cve":"CVE-2026-19766","cvss":9.6,"epss":0.0026,"slug":"cve-2026-19766-hpe-networking-fabric-composer-authentication-bypass-in-os","title":"HPE Networking Fabric Composer authentication bypass in OS","severity":"critical","exploited":false,"published_at":"2026-09-01T20:17:12.76+00:00","url":"https://junglewise.ai/threats/cve-2026-19766-hpe-networking-fabric-composer-authentication-bypass-in-os"}],"high":23,"name":"Hpe Networking Fabric Composer","rank":4,"slug":"networking-fabric-composer","score":122,"vendor":{"name":"Hpe","slug":"hpe"},"critical":5,"max_cvss":10,"max_epss":0.0145,"exploited":0,"vulnerabilities":51,"url":"https://junglewise.ai/threats/technologies/networking-fabric-composer"},{"hub":true,"top":[{"cve":"CVE-2026-72811","cvss":10,"epss":0.0044,"slug":"cve-2026-72811-siyuan-backlink-search-sql-injection-via-unescaped-metadata","title":"SiYuan backlink search SQL injection via unescaped metadata concatenation","severity":"critical","exploited":false,"published_at":"2026-09-03T22:27:50+00:00","url":"https://junglewise.ai/threats/cve-2026-72811-siyuan-backlink-search-sql-injection-via-unescaped-metadata"},{"cve":"CVE-2026-69083","cvss":10,"epss":0.0048,"slug":"cve-2026-69083-siyuan-fulltextsearchassetcontent-sql-injection-and-regexp","title":"SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakout","severity":"critical","exploited":false,"published_at":"2026-09-03T21:01:05+00:00","url":"https://junglewise.ai/threats/cve-2026-69083-siyuan-fulltextsearchassetcontent-sql-injection-and-regexp"},{"cve":"CVE-2026-69084","cvss":10,"epss":0.0157,"slug":"cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock","title":"SiYuan arbitrary SQL execution via searchEmbedBlock","severity":"critical","exploited":false,"published_at":"2026-09-03T20:19:22+00:00","url":"https://junglewise.ai/threats/cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock"}],"high":19,"name":"SiYuan","rank":5,"slug":"siyuan","score":101,"vendor":{"name":"SiYuan","slug":"siyuan"},"critical":4,"max_cvss":10,"max_epss":0.0157,"exploited":0,"vulnerabilities":43,"url":"https://junglewise.ai/threats/technologies/siyuan"},{"hub":true,"top":[{"cve":"CVE-2026-84637","cvss":9.8,"epss":0.0063,"slug":"cve-2026-84637-mozilla-thunderbird-calendar-invitation-code-execution-on-windows","title":"Mozilla Thunderbird calendar invitation code execution on Windows","severity":"critical","exploited":false,"published_at":"2026-09-01T22:17:19.597+00:00","url":"https://junglewise.ai/threats/cve-2026-84637-mozilla-thunderbird-calendar-invitation-code-execution-on-windows"},{"cve":"CVE-2026-84142","cvss":9.8,"epss":0.0056,"slug":"cve-2026-84142-mozilla-thunderbird-memory-corruption-and-security-defects","title":"Mozilla Thunderbird memory corruption and security defects","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.337+00:00","url":"https://junglewise.ai/threats/cve-2026-84142-mozilla-thunderbird-memory-corruption-and-security-defects"},{"cve":"CVE-2026-84141","cvss":9.8,"epss":0.0063,"slug":"cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib","title":"Mozilla Firefox integer overflow in Graphics: ImageLib","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.23+00:00","url":"https://junglewise.ai/threats/cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib"}],"high":10,"name":"Mozilla Thunderbird","rank":6,"slug":"thunderbird","score":100,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":10,"max_cvss":9.8,"max_epss":0.0063,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/thunderbird"},{"hub":true,"top":[{"cve":"CVE-2026-61779","cvss":7.8,"epss":0.0041,"slug":"cve-2026-61779-nvidia-megatron-bridge-deserialization-vulnerability","title":"NVIDIA Megatron Bridge deserialization vulnerability","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:12.923+00:00","url":"https://junglewise.ai/threats/cve-2026-61779-nvidia-megatron-bridge-deserialization-vulnerability"},{"cve":"CVE-2026-61778","cvss":7.8,"epss":0.0041,"slug":"cve-2026-61778-nvidia-megatron-bridge-deserialization-of-untrusted-data","title":"NVIDIA Megatron Bridge deserialization of untrusted data","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:12.813+00:00","url":"https://junglewise.ai/threats/cve-2026-61778-nvidia-megatron-bridge-deserialization-of-untrusted-data"},{"cve":"CVE-2026-61777","cvss":7.8,"epss":0.0041,"slug":"cve-2026-61777-nvidia-megatron-bridge-unsafe-deserialization","title":"NVIDIA Megatron Bridge unsafe deserialization","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:12.697+00:00","url":"https://junglewise.ai/threats/cve-2026-61777-nvidia-megatron-bridge-unsafe-deserialization"}],"high":30,"name":"Nvidia Megatron-Bridge","rank":7,"slug":"megatron-bridge","score":90,"vendor":{"name":"Nvidia","slug":"nvidia"},"critical":0,"max_cvss":7.8,"max_epss":0.0054,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/megatron-bridge"},{"hub":true,"top":[{"cve":"CVE-2026-61779","cvss":7.8,"epss":0.0041,"slug":"cve-2026-61779-nvidia-megatron-bridge-deserialization-vulnerability","title":"NVIDIA Megatron Bridge deserialization vulnerability","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:12.923+00:00","url":"https://junglewise.ai/threats/cve-2026-61779-nvidia-megatron-bridge-deserialization-vulnerability"},{"cve":"CVE-2026-61778","cvss":7.8,"epss":0.0041,"slug":"cve-2026-61778-nvidia-megatron-bridge-deserialization-of-untrusted-data","title":"NVIDIA Megatron Bridge deserialization of untrusted data","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:12.813+00:00","url":"https://junglewise.ai/threats/cve-2026-61778-nvidia-megatron-bridge-deserialization-of-untrusted-data"},{"cve":"CVE-2026-61777","cvss":7.8,"epss":0.0041,"slug":"cve-2026-61777-nvidia-megatron-bridge-unsafe-deserialization","title":"NVIDIA Megatron Bridge unsafe deserialization","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:12.697+00:00","url":"https://junglewise.ai/threats/cve-2026-61777-nvidia-megatron-bridge-unsafe-deserialization"}],"high":30,"name":"Nvidia NeMo Megatron Bridge","rank":8,"slug":"nemo-megatron-bridge","score":90,"vendor":{"name":"Nvidia","slug":"nvidia"},"critical":0,"max_cvss":7.8,"max_epss":0.0054,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/nemo-megatron-bridge"},{"hub":true,"top":[{"cve":"CVE-2026-84142","cvss":9.8,"epss":0.0056,"slug":"cve-2026-84142-mozilla-thunderbird-memory-corruption-and-security-defects","title":"Mozilla Thunderbird memory corruption and security defects","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.337+00:00","url":"https://junglewise.ai/threats/cve-2026-84142-mozilla-thunderbird-memory-corruption-and-security-defects"},{"cve":"CVE-2026-84141","cvss":9.8,"epss":0.0063,"slug":"cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib","title":"Mozilla Firefox integer overflow in Graphics: ImageLib","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.23+00:00","url":"https://junglewise.ai/threats/cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib"},{"cve":"CVE-2026-84140","cvss":9.8,"epss":0.0029,"slug":"cve-2026-84140-mozilla-firefox-site-isolation-issue-in-dom-navigation-component","title":"Mozilla Firefox site isolation issue in DOM Navigation component","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.127+00:00","url":"https://junglewise.ai/threats/cve-2026-84140-mozilla-firefox-site-isolation-issue-in-dom-navigation-component"}],"high":6,"name":"Mozilla Firefox","rank":9,"slug":"firefox","score":76,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":8,"max_cvss":9.8,"max_epss":0.0063,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/firefox"},{"hub":true,"top":[{"cve":"CVE-2026-72811","cvss":10,"epss":0.0044,"slug":"cve-2026-72811-siyuan-backlink-search-sql-injection-via-unescaped-metadata","title":"SiYuan backlink search SQL injection via unescaped metadata concatenation","severity":"critical","exploited":false,"published_at":"2026-09-03T22:27:50+00:00","url":"https://junglewise.ai/threats/cve-2026-72811-siyuan-backlink-search-sql-injection-via-unescaped-metadata"},{"cve":"CVE-2026-69083","cvss":10,"epss":0.0048,"slug":"cve-2026-69083-siyuan-fulltextsearchassetcontent-sql-injection-and-regexp","title":"SiYuan fullTextSearchAssetContent SQL injection and REGEXP breakout","severity":"critical","exploited":false,"published_at":"2026-09-03T21:01:05+00:00","url":"https://junglewise.ai/threats/cve-2026-69083-siyuan-fulltextsearchassetcontent-sql-injection-and-regexp"},{"cve":"CVE-2026-69084","cvss":10,"epss":0.0157,"slug":"cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock","title":"SiYuan arbitrary SQL execution via searchEmbedBlock","severity":"critical","exploited":false,"published_at":"2026-09-03T20:19:22+00:00","url":"https://junglewise.ai/threats/cve-2026-69084-siyuan-arbitrary-sql-execution-via-searchembedblock"}],"high":14,"name":"Go Github.com/Siyuan-Note/Siyuan/Kernel","rank":10,"slug":"github-com-siyuan-note-siyuan-kernel","score":73,"vendor":{"name":"Go","slug":"go"},"critical":3,"max_cvss":10,"max_epss":0.0157,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"hub":true,"top":[{"cve":"CVE-2026-86189","cvss":9.8,"epss":0.0071,"slug":"cve-2026-86189-wwbn-avideo-path-traversal-in-notify-ffmpeg-json-php","title":"WWBN AVideo path traversal in notify.ffmpeg.json.php","severity":"critical","exploited":false,"published_at":"2026-09-05T13:18:14+00:00","url":"https://junglewise.ai/threats/cve-2026-86189-wwbn-avideo-path-traversal-in-notify-ffmpeg-json-php"},{"cve":"CVE-2026-85154","cvss":9.8,"epss":0.0064,"slug":"cve-2026-85154-wwbn-avideo-authentication-bypass-in-video-id-hash-credential","title":"WWBN AVideo authentication bypass in video_id_hash credential","severity":"critical","exploited":false,"published_at":"2026-09-03T13:06:22.067+00:00","url":"https://junglewise.ai/threats/cve-2026-85154-wwbn-avideo-authentication-bypass-in-video-id-hash-credential"},{"cve":"CVE-2026-84480","cvss":9.8,"epss":0.0051,"slug":"cve-2026-84480-wwbn-avideo-password-recovery-token-expiration-bypass","title":"WWBN AVideo password recovery token expiration bypass","severity":"critical","exploited":false,"published_at":"2026-09-01T23:17:22.22+00:00","url":"https://junglewise.ai/threats/cve-2026-84480-wwbn-avideo-password-recovery-token-expiration-bypass"}],"high":10,"name":"WWBN AVideo","rank":11,"slug":"avideo","score":72,"vendor":{"name":"WWBN","slug":"wwbn"},"critical":5,"max_cvss":9.8,"max_epss":0.0071,"exploited":0,"vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/avideo"},{"hub":true,"top":[{"cve":"CVE-2026-84141","cvss":9.8,"epss":0.0063,"slug":"cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib","title":"Mozilla Firefox integer overflow in Graphics: ImageLib","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.23+00:00","url":"https://junglewise.ai/threats/cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib"},{"cve":"CVE-2026-84140","cvss":9.8,"epss":0.0029,"slug":"cve-2026-84140-mozilla-firefox-site-isolation-issue-in-dom-navigation-component","title":"Mozilla Firefox site isolation issue in DOM Navigation component","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.127+00:00","url":"https://junglewise.ai/threats/cve-2026-84140-mozilla-firefox-site-isolation-issue-in-dom-navigation-component"},{"cve":"CVE-2026-84134","cvss":9.8,"epss":0.0057,"slug":"cve-2026-84134-mozilla-firefox-other-issue-in-profile-backup-component","title":"Mozilla Firefox other issue in Profile Backup component","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:07.45+00:00","url":"https://junglewise.ai/threats/cve-2026-84134-mozilla-firefox-other-issue-in-profile-backup-component"}],"high":4,"name":"Mozilla Firefox ESR","rank":12,"slug":"firefox-esr","score":62,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":7,"max_cvss":9.8,"max_epss":0.0063,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/firefox-esr"},{"hub":true,"top":[{"cve":"CVE-2026-86060","cvss":9.8,"epss":0.0185,"slug":"cve-2026-86060-mikrotik-routeros-argument-delimiter-neutralization-privilege","title":"RouterOS contains an argument-handling flaw in the SSH login\npath involving usernames that begin with a prohibited character, allowing for t","severity":"critical","exploited":true,"published_at":"2026-09-05T20:17:18.703+00:00","url":"https://junglewise.ai/threats/cve-2026-86060-mikrotik-routeros-argument-delimiter-neutralization-privilege"},{"cve":"CVE-2026-67277","cvss":8.2,"epss":0.0156,"slug":"cve-2026-67277-mikrotik-routeros-missing-authentication-in-btest-service","title":"RouterOS accepts a \"related\" btest connection before the corresponding primary session has completed authentication. An unauthenticated clie","severity":"critical","exploited":true,"published_at":"2026-09-05T20:17:18.12+00:00","url":"https://junglewise.ai/threats/cve-2026-67277-mikrotik-routeros-missing-authentication-in-btest-service"},{"cve":"CVE-2026-67279","cvss":6.5,"epss":0.0071,"slug":"cve-2026-67279-mikrotik-routeros-improper-behavioral-workflow-enforcement","title":"RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an","severity":"critical","exploited":true,"published_at":"2026-09-05T20:17:18.39+00:00","url":"https://junglewise.ai/threats/cve-2026-67279-mikrotik-routeros-improper-behavioral-workflow-enforcement"}],"high":0,"name":"MikroTik RouterOS","rank":13,"slug":"routeros","score":48,"vendor":{"name":"MikroTik","slug":"mikrotik"},"critical":3,"max_cvss":9.8,"max_epss":0.0185,"exploited":3,"vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/routeros"},{"hub":true,"top":[{"cve":"CVE-2026-85223","cvss":9.9,"epss":0.0328,"slug":"cve-2026-85223-d-link-dns-340l-os-command-injection-in-dropbox-cgi","title":"D-Link DNS-340L OS command injection in dropbox.cgi","severity":"critical","exploited":false,"published_at":"2026-09-03T22:18:24.08+00:00","url":"https://junglewise.ai/threats/cve-2026-85223-d-link-dns-340l-os-command-injection-in-dropbox-cgi"},{"cve":"CVE-2026-82692","cvss":9.9,"epss":0.0328,"slug":"cve-2026-82692-d-link-dns-340l-and-dns-345-os-command-injection-in-iscsi-mgr-cgi","title":"D-Link DNS-340L and DNS-345 OS command injection in iscsi_mgr.cgi","severity":"critical","exploited":false,"published_at":"2026-08-31T13:18:29.387+00:00","url":"https://junglewise.ai/threats/cve-2026-82692-d-link-dns-340l-and-dns-345-os-command-injection-in-iscsi-mgr-cgi"},{"cve":"CVE-2026-82689","cvss":9.9,"epss":0.0328,"slug":"cve-2026-82689-d-link-dns-sharecenter-os-command-injection-in-isomount-mgr-cgi","title":"D-Link DNS ShareCenter OS command injection in isomount_mgr.cgi","severity":"critical","exploited":false,"published_at":"2026-08-31T12:17:57.763+00:00","url":"https://junglewise.ai/threats/cve-2026-82689-d-link-dns-sharecenter-os-command-injection-in-isomount-mgr-cgi"}],"high":0,"name":"D-Link DNS-340L","rank":14,"slug":"dns-340l","score":42,"vendor":{"name":"D-Link","slug":"d-link"},"critical":7,"max_cvss":9.9,"max_epss":0.0361,"exploited":0,"vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/dns-340l"},{"hub":true,"top":[{"cve":"CVE-2026-83619","cvss":4,"epss":0.0052,"slug":"cve-2026-83619-xmldom-end-tag-whitespace-trim-redos","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the relea","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.657+00:00","url":"https://junglewise.ai/threats/cve-2026-83619-xmldom-end-tag-whitespace-trim-redos"},{"cve":"CVE-2026-83618","cvss":4,"epss":0.0057,"slug":"cve-2026-83618-xmldom-requirewellformed-doctype-validation-bypass-via-line","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requ","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.48+00:00","url":"https://junglewise.ai/threats/cve-2026-83618-xmldom-requirewellformed-doctype-validation-bypass-via-line"},{"cve":"CVE-2026-83617","cvss":4,"epss":0.0057,"slug":"cve-2026-83617-xmldom-xmlserializer-requirewellformed-bypass-via-line-terminator","title":"xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requ","severity":"high","exploited":false,"published_at":"2026-09-01T15:17:40.273+00:00","url":"https://junglewise.ai/threats/cve-2026-83617-xmldom-xmlserializer-requirewellformed-bypass-via-line-terminator"}],"high":13,"name":"Npm @Xmldom/Xmldom","rank":15,"slug":"xmldom-xmldom","score":41,"vendor":{"name":"Npm","slug":"npm"},"critical":0,"max_cvss":4,"max_epss":0.0062,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/xmldom-xmldom"},{"hub":true,"top":[{"cve":"CVE-2026-85440","cvss":9.8,"epss":0.0103,"slug":"cve-2026-85440-moos-core-moos-pre-authentication-heap-overflow-in-mooscommpkt","title":"MOOS core-moos pre-authentication heap overflow in MOOSCommPkt","severity":"critical","exploited":false,"published_at":"2026-09-03T23:17:23.59+00:00","url":"https://junglewise.ai/threats/cve-2026-85440-moos-core-moos-pre-authentication-heap-overflow-in-mooscommpkt"},{"cve":"CVE-2026-85428","cvss":9.8,"epss":0.0082,"slug":"cve-2026-85428-moos-core-moos-authentication-bypass-in-moosdb-http-server","title":"MOOS core-moos authentication bypass in MOOSDB HTTP server","severity":"critical","exploited":false,"published_at":"2026-09-03T23:17:21.77+00:00","url":"https://junglewise.ai/threats/cve-2026-85428-moos-core-moos-authentication-bypass-in-moosdb-http-server"},{"cve":"CVE-2026-85424","cvss":9.8,"epss":0.0082,"slug":"cve-2026-85424-moos-core-moos-authentication-bypass-in-wire-protocol","title":"MOOS core-moos authentication bypass in wire protocol","severity":"critical","exploited":false,"published_at":"2026-09-03T23:17:21.17+00:00","url":"https://junglewise.ai/threats/cve-2026-85424-moos-core-moos-authentication-bypass-in-wire-protocol"}],"high":7,"name":"MOOS Core-Moos","rank":16,"slug":"core-moos","score":41,"vendor":{"name":"MOOS","slug":"moos"},"critical":3,"max_cvss":9.8,"max_epss":0.0103,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/core-moos"},{"hub":true,"top":[{"cve":"CVE-2026-63137","cvss":8.3,"epss":0.005,"slug":"cve-2026-63137-elastic-kibana-privilege-escalation-in-workflows-access-control","title":"Elastic Kibana privilege escalation in Workflows access control","severity":"high","exploited":false,"published_at":"2026-09-01T20:17:15.117+00:00","url":"https://junglewise.ai/threats/cve-2026-63137-elastic-kibana-privilege-escalation-in-workflows-access-control"},{"cve":"CVE-2026-82302","cvss":8.1,"epss":0.0039,"slug":"cve-2026-82302-elastic-kibana-authorization-bypass-in-access-control","title":"Elastic Kibana authorization bypass in access control","severity":"high","exploited":false,"published_at":"2026-09-03T19:17:29.827+00:00","url":"https://junglewise.ai/threats/cve-2026-82302-elastic-kibana-authorization-bypass-in-access-control"},{"cve":"CVE-2026-78583","cvss":8.1,"epss":0.0039,"slug":"cve-2026-78583-elastic-kibana-privilege-escalation-via-fleet-integration","title":"Elastic Kibana privilege escalation via Fleet integration validation bypass","severity":"high","exploited":false,"published_at":"2026-09-03T19:17:28.55+00:00","url":"https://junglewise.ai/threats/cve-2026-78583-elastic-kibana-privilege-escalation-via-fleet-integration"}],"high":5,"name":"Elastic Kibana","rank":17,"slug":"kibana","score":40,"vendor":{"name":"Elastic","slug":"elastic"},"critical":0,"max_cvss":8.3,"max_epss":0.0051,"exploited":0,"vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/kibana"},{"hub":true,"top":[{"cve":"CVE-2026-58574","cvss":9.8,"epss":0.0063,"slug":"cve-2026-58574-dell-powerstore-missing-authentication-in-management-interface","title":"Dell PowerStore missing authentication in management interface","severity":"critical","exploited":false,"published_at":"2026-08-31T07:17:44.743+00:00","url":"https://junglewise.ai/threats/cve-2026-58574-dell-powerstore-missing-authentication-in-management-interface"},{"cve":"CVE-2026-58566","cvss":8.8,"epss":0.0042,"slug":"cve-2026-58566-dell-powerstore-incorrect-authorization-leading-to-privilege","title":"Dell PowerStore incorrect authorization leading to privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-01T17:17:31.507+00:00","url":"https://junglewise.ai/threats/cve-2026-58566-dell-powerstore-incorrect-authorization-leading-to-privilege"},{"cve":"CVE-2026-79682","cvss":8.8,"epss":0.0091,"slug":"cve-2026-79682-dell-powerstore-command-injection-privilege-escalation","title":"Dell PowerStore command injection privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-01T16:17:19.557+00:00","url":"https://junglewise.ai/threats/cve-2026-79682-dell-powerstore-command-injection-privilege-escalation"}],"high":11,"name":"Dell PowerStore","rank":18,"slug":"powerstore","score":40,"vendor":{"name":"Dell","slug":"dell"},"critical":1,"max_cvss":9.8,"max_epss":0.0091,"exploited":0,"vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/powerstore"},{"hub":true,"top":[{"cve":"CVE-2026-19298","cvss":8.8,"epss":0.005,"slug":"cve-2026-19298-ibm-langflow-oss-authorization-bypass-in-flow-build-endpoint","title":"IBM Langflow OSS authorization bypass in flow-build endpoint","severity":"high","exploited":false,"published_at":"2026-09-04T16:17:21.9+00:00","url":"https://junglewise.ai/threats/cve-2026-19298-ibm-langflow-oss-authorization-bypass-in-flow-build-endpoint"},{"cve":"CVE-2026-19305","cvss":8.6,"epss":0.0029,"slug":"cve-2026-19305-ibm-langflow-oss-server-side-request-forgery-in-url-validation","title":"IBM Langflow OSS server-side request forgery in URL validation","severity":"high","exploited":false,"published_at":"2026-09-04T16:17:24.323+00:00","url":"https://junglewise.ai/threats/cve-2026-19305-ibm-langflow-oss-server-side-request-forgery-in-url-validation"},{"cve":"CVE-2026-84351","cvss":8.3,"epss":0.0044,"slug":"cve-2026-84351-google-chrome-buffer-overflow-in-gpu","title":"Google Chrome buffer overflow in GPU","severity":"high","exploited":false,"published_at":"2026-09-02T00:18:28.983+00:00","url":"https://junglewise.ai/threats/cve-2026-84351-google-chrome-buffer-overflow-in-gpu"}],"high":8,"name":"Microsoft Windows ","rank":19,"slug":"windows-","score":36,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":0,"max_cvss":8.8,"max_epss":0.005,"exploited":0,"vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2026-52777","cvss":9.4,"epss":0.0028,"slug":"cve-2026-52777-yeswiki-php-object-injection-in-bazarimportaction","title":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImport","severity":"critical","exploited":false,"published_at":"2026-09-05T00:17:20.663+00:00","url":"https://junglewise.ai/threats/cve-2026-52777-yeswiki-php-object-injection-in-bazarimportaction"},{"cve":"CVE-2026-52766","cvss":9.1,"epss":0.0058,"slug":"cve-2026-52766-yeswiki-missing-authorization-in-erasespamedcomments-action","title":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.","severity":"critical","exploited":false,"published_at":"2026-09-05T00:17:19.393+00:00","url":"https://junglewise.ai/threats/cve-2026-52766-yeswiki-missing-authorization-in-erasespamedcomments-action"},{"cve":"CVE-2026-52775","cvss":8.8,"epss":0.0048,"slug":"cve-2026-52775-yeswiki-authenticated-sql-injection-in-reactionmanager","title":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vuln","severity":"high","exploited":false,"published_at":"2026-09-05T00:17:20.52+00:00","url":"https://junglewise.ai/threats/cve-2026-52775-yeswiki-authenticated-sql-injection-in-reactionmanager"}],"high":6,"name":"YesWiki","rank":20,"slug":"yeswiki","score":34,"vendor":{"name":"YesWiki","slug":"yeswiki"},"critical":2,"max_cvss":9.4,"max_epss":0.0078,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/yeswiki"},{"hub":true,"top":[{"cve":"CVE-2026-52777","cvss":9.4,"epss":0.0028,"slug":"cve-2026-52777-yeswiki-php-object-injection-in-bazarimportaction","title":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImport","severity":"critical","exploited":false,"published_at":"2026-09-05T00:17:20.663+00:00","url":"https://junglewise.ai/threats/cve-2026-52777-yeswiki-php-object-injection-in-bazarimportaction"},{"cve":"CVE-2026-52766","cvss":9.1,"epss":0.0058,"slug":"cve-2026-52766-yeswiki-missing-authorization-in-erasespamedcomments-action","title":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.","severity":"critical","exploited":false,"published_at":"2026-09-05T00:17:19.393+00:00","url":"https://junglewise.ai/threats/cve-2026-52766-yeswiki-missing-authorization-in-erasespamedcomments-action"},{"cve":"CVE-2026-52775","cvss":8.8,"epss":0.0048,"slug":"cve-2026-52775-yeswiki-authenticated-sql-injection-in-reactionmanager","title":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vuln","severity":"high","exploited":false,"published_at":"2026-09-05T00:17:20.52+00:00","url":"https://junglewise.ai/threats/cve-2026-52775-yeswiki-authenticated-sql-injection-in-reactionmanager"}],"high":6,"name":"Composer Yeswiki/Yeswiki","rank":21,"slug":"yeswiki-yeswiki","score":34,"vendor":{"name":"Composer","slug":"composer"},"critical":2,"max_cvss":9.4,"max_epss":0.0078,"exploited":0,"vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/yeswiki-yeswiki"},{"hub":true,"top":[{"cve":"CVE-2026-84141","cvss":9.8,"epss":0.0063,"slug":"cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib","title":"Mozilla Firefox integer overflow in Graphics: ImageLib","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.23+00:00","url":"https://junglewise.ai/threats/cve-2026-84141-mozilla-firefox-integer-overflow-in-graphics-imagelib"},{"cve":"CVE-2026-84140","cvss":9.8,"epss":0.0029,"slug":"cve-2026-84140-mozilla-firefox-site-isolation-issue-in-dom-navigation-component","title":"Mozilla Firefox site isolation issue in DOM Navigation component","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:08.127+00:00","url":"https://junglewise.ai/threats/cve-2026-84140-mozilla-firefox-site-isolation-issue-in-dom-navigation-component"},{"cve":"CVE-2026-84134","cvss":9.8,"epss":0.0057,"slug":"cve-2026-84134-mozilla-firefox-other-issue-in-profile-backup-component","title":"Mozilla Firefox other issue in Profile Backup component","severity":"critical","exploited":false,"published_at":"2026-09-01T13:20:07.45+00:00","url":"https://junglewise.ai/threats/cve-2026-84134-mozilla-firefox-other-issue-in-profile-backup-component"}],"high":4,"name":"Mozilla Thunderbird-Esr","rank":22,"slug":"thunderbird-esr","score":34,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":3,"max_cvss":9.8,"max_epss":0.0063,"exploited":0,"vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/thunderbird-esr"},{"hub":true,"top":[{"cve":"CVE-2026-19931","cvss":9.8,"epss":0.0075,"slug":"cve-2026-19931-curl-negotiate-authentication-connection-reuse","title":"curl Negotiate authentication connection reuse","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.733+00:00","url":"https://junglewise.ai/threats/cve-2026-19931-curl-negotiate-authentication-connection-reuse"},{"cve":"CVE-2026-18924","cvss":9.1,"epss":0.0058,"slug":"cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free","title":"curl libcurl HTTP/2 server push use-after-free","severity":"critical","exploited":false,"published_at":"2026-09-06T18:17:20.553+00:00","url":"https://junglewise.ai/threats/cve-2026-18924-curl-libcurl-http-2-server-push-use-after-free"},{"cve":"CVE-2026-82209","cvss":8.2,"epss":0.0052,"slug":"cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie","title":"curl Public Suffix List domain boundary check bypass in cookie handling","severity":"high","exploited":false,"published_at":"2026-09-06T18:17:22.847+00:00","url":"https://junglewise.ai/threats/cve-2026-82209-curl-public-suffix-list-domain-boundary-check-bypass-in-cookie"}],"high":7,"name":"Haxx Curl","rank":23,"slug":"curl","score":33,"vendor":{"name":"Haxx","slug":"haxx"},"critical":2,"max_cvss":9.8,"max_epss":0.009,"exploited":0,"vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/curl"},{"hub":true,"top":[{"cve":"CVE-2026-84795","cvss":9.8,"epss":0.0051,"slug":"cve-2026-84795-craft-cms-privilege-escalation-via-admin-flag-inheritance-in-user","title":"Craft CMS privilege escalation via admin flag inheritance in user registration","severity":"critical","exploited":false,"published_at":"2026-09-02T12:17:16.093+00:00","url":"https://junglewise.ai/threats/cve-2026-84795-craft-cms-privilege-escalation-via-admin-flag-inheritance-in-user"},{"cve":"CVE-2026-84801","cvss":8.8,"epss":0.0044,"slug":"cve-2026-84801-craft-cms-privilege-escalation-via-administrateusers-permission","title":"Craft CMS privilege escalation via administrateUsers permission","severity":"high","exploited":false,"published_at":"2026-09-02T12:17:16.91+00:00","url":"https://junglewise.ai/threats/cve-2026-84801-craft-cms-privilege-escalation-via-administrateusers-permission"},{"cve":"CVE-2026-85380","cvss":7.3,"epss":0.005,"slug":"cve-2026-85380-light0011-cms-server-side-request-forgery-in-ueditor","title":"light0011 cms server-side request forgery in UEditor","severity":"high","exploited":false,"published_at":"2026-09-04T01:17:22.71+00:00","url":"https://junglewise.ai/threats/cve-2026-85380-light0011-cms-server-side-request-forgery-in-ueditor"}],"high":6,"name":"Sitecore CMS","rank":24,"slug":"cms","score":32,"vendor":{"name":"Sitecore","slug":"sitecore"},"critical":1,"max_cvss":9.8,"max_epss":0.0057,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/cms"},{"hub":false,"top":[{"cve":"CVE-2026-83548","cvss":10,"epss":0.0876,"slug":"cve-2026-83548-sonicwall-sma1000-server-side-request-forgery","title":"A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A r","severity":"critical","exploited":true,"published_at":"2026-09-01T22:17:13.17+00:00","url":"https://junglewise.ai/threats/cve-2026-83548-sonicwall-sma1000-server-side-request-forgery"},{"cve":"CVE-2026-83549","cvss":7.8,"epss":0.1076,"slug":"cve-2026-83549-sonicwall-sma1000-os-command-injection","title":"Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identi","severity":"critical","exploited":true,"published_at":"2026-09-01T22:17:13.29+00:00","url":"https://junglewise.ai/threats/cve-2026-83549-sonicwall-sma1000-os-command-injection"}],"high":0,"name":"SonicWall SMA1000","rank":25,"slug":"sma1000","score":32,"vendor":{"name":"SonicWall","slug":"sonicwall"},"critical":2,"max_cvss":10,"max_epss":0.1076,"exploited":2,"vulnerabilities":2}],"previous":{"key":"2026-08-24","top":"Google Chrome","period":{"end":"2026-08-30","start":"2026-08-24"},"totals":{"high":968,"critical":331,"exploited":10,"technologies":1154,"vulnerabilities":2819},"url":"https://junglewise.ai/threats/weekly/2026-08-24"},"next":{"key":"2026-09-07","top":"Linux Kernel","period":{"end":"2026-09-13","start":"2026-09-07"},"totals":{"high":1701,"critical":319,"exploited":9,"technologies":1480,"vulnerabilities":3792},"url":"https://junglewise.ai/threats/weekly/2026-09-07"}}