Weekly report
Most vulnerable technologies: week of 7 to 13 September 2026 (week 37)
Final report, published . It does not change.
In the week of 7 to 13 September 2026, Junglewise Threat Intelligence recorded 3,792 new vulnerabilities: 319 critical, 1,701 high and 9 exploited in the wild. The most vulnerable technology was Linux Kernel, with 420 vulnerabilities (66 critical), followed by Microsoft Windows (399) and Google Chrome (227).
- New vulnerabilities
- 3,792
- Critical
- 319
- Exploited in the wild
- 9
- Technologies affected
- 1,480
Ranking
Most affected vendors
- 1.Microsoft980 vulnerabilities, 49 critical, 3 exploited
- 2.Linux420 vulnerabilities, 66 critical, 0 exploited
- 3.Google321 vulnerabilities, 37 critical, 1 exploited
- 4.Dell115 vulnerabilities, 7 critical, 0 exploited
- 5.Adobe61 vulnerabilities, 6 critical, 1 exploited
- 6.IBM51 vulnerabilities, 8 critical, 0 exploited
- 7.WWBN61 vulnerabilities, 1 critical, 0 exploited
- 8.Apple45 vulnerabilities, 5 critical, 0 exploited
- 9.Go33 vulnerabilities, 5 critical, 0 exploited
- 10.Amazon19 vulnerabilities, 3 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1…criticalexploited in the wildCVSS 10EPSS 91.4%
- CVE-2026-75650: Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that…criticalexploited in the wildCVSS 10EPSS 4.0%
- CVE-2026-84869: A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session…criticalexploited in the wildCVSS 9.9EPSS 0.9%
- CVE-2026-19490: Citrix NetScaler authentication bypass via alternate pathcriticalexploited in the wildCVSS 9.8EPSS 7.0%
- CVE-2026-85102: Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an…criticalexploited in the wildCVSS 9.8EPSS 1.0%
- CVE-2026-87491: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code…criticalexploited in the wildCVSS 8.8EPSS 3.1%
- CVE-2026-85880: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.criticalexploited in the wildCVSS 7.8EPSS 3.6%
- CVE-2026-81963: Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to…criticalexploited in the wildCVSS 7.8EPSS 0.4%
- CVE-2026-42018: JFrog Artifactory improper authentication vulnerabilitycriticalexploited in the wildEPSS 9.8%
- CVE-2026-82004: Adobe Campaign Classic OS command injectioncriticalCVSS 10EPSS 3.3%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-09-07.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 7 to 13 September 2026 (week 37)", https://junglewise.ai/threats/weekly/2026-09-07, 26 September 2026.