{"schema_version":1,"title":"Most vulnerable technologies: week of 7 to 13 September 2026 (week 37)","summary":"In the week of 7 to 13 September 2026, Junglewise Threat Intelligence recorded 3,792 new vulnerabilities: 319 critical, 1,701 high and 9 exploited in the wild. The most vulnerable technology was Linux Kernel, with 420 vulnerabilities (66 critical), followed by Microsoft Windows  (399) and Google Chrome (227).","url":"https://junglewise.ai/threats/weekly/2026-09-07","json_url":"https://junglewise.ai/threats/weekly/2026-09-07.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/weekly/2026-09-07","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"week","period":{"end":"2026-09-13","start":"2026-09-07"},"totals":{"high":1701,"critical":319,"exploited":9,"technologies":1480,"vulnerabilities":3792},"notable":[{"cve":"CVE-2026-85706","cvss":10,"epss":0.9143,"slug":"cve-2026-85706-gitlab-community-and-enterprise-edition-path-traversal-in-commits","title":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.","severity":"critical","exploited":true,"published_at":"2026-09-12T03:16:30.473+00:00","url":"https://junglewise.ai/threats/cve-2026-85706-gitlab-community-and-enterprise-edition-path-traversal-in-commits"},{"cve":"CVE-2026-75650","cvss":10,"epss":0.0395,"slug":"cve-2026-75650-adobe-commerce-and-magento-improper-neutralization-in-template","title":"Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in ar","severity":"critical","exploited":true,"published_at":"2026-09-07T21:17:30.863+00:00","url":"https://junglewise.ai/threats/cve-2026-75650-adobe-commerce-and-magento-improper-neutralization-in-template"},{"cve":"CVE-2026-84869","cvss":9.9,"epss":0.0092,"slug":"cve-2026-84869-connectwise-screenconnect-unauthorized-file-transfer-and","title":"A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorizatio","severity":"critical","exploited":true,"published_at":"2026-09-08T20:18:51.147+00:00","url":"https://junglewise.ai/threats/cve-2026-84869-connectwise-screenconnect-unauthorized-file-transfer-and"},{"cve":"CVE-2026-19490","cvss":9.8,"epss":0.0701,"slug":"cve-2026-19490-citrix-netscaler-authentication-bypass-via-alternate-path","title":"Citrix NetScaler authentication bypass via alternate path","severity":"critical","exploited":true,"published_at":"2026-09-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-19490-citrix-netscaler-authentication-bypass-via-alternate-path"},{"cve":"CVE-2026-85102","cvss":9.8,"epss":0.0099,"slug":"cve-2026-85102-check-point-security-gateway-and-spark-firewall-improper","title":"Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote att","severity":"critical","exploited":true,"published_at":"2026-09-09T13:20:43.793+00:00","url":"https://junglewise.ai/threats/cve-2026-85102-check-point-security-gateway-and-spark-firewall-improper"},{"cve":"CVE-2026-87491","cvss":8.8,"epss":0.0314,"slug":"cve-2026-87491-google-chromium-v8-out-of-bounds-write-in-javascript-engine","title":"Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via","severity":"critical","exploited":true,"published_at":"2026-09-09T01:17:05.887+00:00","url":"https://junglewise.ai/threats/cve-2026-87491-google-chromium-v8-out-of-bounds-write-in-javascript-engine"},{"cve":"CVE-2026-85880","cvss":7.8,"epss":0.0362,"slug":"cve-2026-85880-microsoft-windows-heap-based-buffer-overflow-in-advanced-local","title":"Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.","severity":"critical","exploited":true,"published_at":"2026-09-08T18:21:14.087+00:00","url":"https://junglewise.ai/threats/cve-2026-85880-microsoft-windows-heap-based-buffer-overflow-in-advanced-local"},{"cve":"CVE-2026-81963","cvss":7.8,"epss":0.0039,"slug":"cve-2026-81963-microsoft-windows-privilege-escalation-via-link-following-in","title":"Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges l","severity":"critical","exploited":true,"published_at":"2026-09-08T18:21:00.09+00:00","url":"https://junglewise.ai/threats/cve-2026-81963-microsoft-windows-privilege-escalation-via-link-following-in"},{"cve":"CVE-2026-42018","epss":0.0981,"slug":"cve-2026-42018-jfrog-artifactory-improper-authentication-vulnerability","title":"JFrog Artifactory improper authentication vulnerability","severity":"critical","exploited":true,"published_at":"2026-09-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-42018-jfrog-artifactory-improper-authentication-vulnerability"},{"cve":"CVE-2026-82004","cvss":10,"epss":0.0325,"slug":"cve-2026-82004-adobe-campaign-classic-os-command-injection","title":"Adobe Campaign Classic OS command injection","severity":"critical","exploited":false,"published_at":"2026-09-08T19:19:59.743+00:00","url":"https://junglewise.ai/threats/cve-2026-82004-adobe-campaign-classic-os-command-injection"}],"vendors":[{"hub":true,"high":679,"name":"Microsoft","rank":1,"slug":"microsoft","critical":49,"exploited":3,"vulnerabilities":980,"url":"https://junglewise.ai/threats/vendors/microsoft"},{"hub":true,"high":195,"name":"Linux","rank":2,"slug":"linux","critical":66,"exploited":0,"vulnerabilities":420,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":112,"name":"Google","rank":3,"slug":"google","critical":37,"exploited":1,"vulnerabilities":321,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":35,"name":"Dell","rank":4,"slug":"dell","critical":7,"exploited":0,"vulnerabilities":115,"url":"https://junglewise.ai/threats/vendors/dell"},{"hub":true,"high":42,"name":"Adobe","rank":5,"slug":"adobe","critical":6,"exploited":1,"vulnerabilities":61,"url":"https://junglewise.ai/threats/vendors/adobe"},{"hub":true,"high":33,"name":"IBM","rank":6,"slug":"ibm","critical":8,"exploited":0,"vulnerabilities":51,"url":"https://junglewise.ai/threats/vendors/ibm"},{"hub":true,"high":27,"name":"WWBN","rank":7,"slug":"wwbn","critical":1,"exploited":0,"vulnerabilities":61,"url":"https://junglewise.ai/threats/vendors/wwbn"},{"hub":true,"high":20,"name":"Apple","rank":8,"slug":"apple","critical":5,"exploited":0,"vulnerabilities":45,"url":"https://junglewise.ai/threats/vendors/apple"},{"hub":true,"high":12,"name":"Go","rank":9,"slug":"go","critical":5,"exploited":0,"vulnerabilities":33,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":16,"name":"Amazon","rank":10,"slug":"amazon","critical":3,"exploited":0,"vulnerabilities":19,"url":"https://junglewise.ai/threats/vendors/amazon"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-89712","cvss":9.8,"epss":0.0076,"slug":"cve-2026-89712-linux-kernel-nfsd-use-after-free-in-ssc-expire-umount","title":"Linux kernel NFSD use-after-free in ssc_expire_umount","severity":"critical","exploited":false,"published_at":"2026-09-11T20:19:58.62+00:00","url":"https://junglewise.ai/threats/cve-2026-89712-linux-kernel-nfsd-use-after-free-in-ssc-expire-umount"},{"cve":"CVE-2026-89703","cvss":9.8,"epss":0.0065,"slug":"cve-2026-89703-linux-kernel-nfsd-use-after-free-in-delegation-handling","title":"Linux kernel nfsd use-after-free in delegation handling","severity":"critical","exploited":false,"published_at":"2026-09-11T20:19:57.537+00:00","url":"https://junglewise.ai/threats/cve-2026-89703-linux-kernel-nfsd-use-after-free-in-delegation-handling"},{"cve":"CVE-2026-89702","cvss":9.8,"epss":0.0067,"slug":"cve-2026-89702-linux-kernel-nfsd-fh-verify-ring-buffer-overflow","title":"Linux kernel nfsd fh_verify ring-buffer overflow","severity":"critical","exploited":false,"published_at":"2026-09-11T20:19:57.413+00:00","url":"https://junglewise.ai/threats/cve-2026-89702-linux-kernel-nfsd-fh-verify-ring-buffer-overflow"}],"high":195,"name":"Linux Kernel","rank":1,"slug":"kernel","score":1140,"vendor":{"name":"Linux","slug":"linux"},"critical":66,"max_cvss":9.8,"max_epss":0.0076,"exploited":0,"vulnerabilities":420,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-85880","cvss":7.8,"epss":0.0362,"slug":"cve-2026-85880-microsoft-windows-heap-based-buffer-overflow-in-advanced-local","title":"Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.","severity":"critical","exploited":true,"published_at":"2026-09-08T18:21:14.087+00:00","url":"https://junglewise.ai/threats/cve-2026-85880-microsoft-windows-heap-based-buffer-overflow-in-advanced-local"},{"cve":"CVE-2026-81963","cvss":7.8,"epss":0.0039,"slug":"cve-2026-81963-microsoft-windows-privilege-escalation-via-link-following-in","title":"Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges l","severity":"critical","exploited":true,"published_at":"2026-09-08T18:21:00.09+00:00","url":"https://junglewise.ai/threats/cve-2026-81963-microsoft-windows-privilege-escalation-via-link-following-in"},{"cve":"CVE-2026-73025","cvss":9.8,"epss":0.009,"slug":"cve-2026-73025-microsoft-windows-iscsi-weak-authentication-bypass","title":"Microsoft Windows iSCSI weak authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-08T18:20:32.49+00:00","url":"https://junglewise.ai/threats/cve-2026-73025-microsoft-windows-iscsi-weak-authentication-bypass"}],"high":295,"name":"Microsoft Windows ","rank":2,"slug":"windows-","score":1094,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":17,"max_cvss":9.8,"max_epss":0.0362,"exploited":2,"vulnerabilities":399,"url":"https://junglewise.ai/threats/technologies/windows-"},{"hub":true,"top":[{"cve":"CVE-2026-87491","cvss":8.8,"epss":0.0314,"slug":"cve-2026-87491-google-chromium-v8-out-of-bounds-write-in-javascript-engine","title":"Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via","severity":"critical","exploited":true,"published_at":"2026-09-09T01:17:05.887+00:00","url":"https://junglewise.ai/threats/cve-2026-87491-google-chromium-v8-out-of-bounds-write-in-javascript-engine"},{"cve":"CVE-2026-87595","cvss":9.8,"epss":0.0042,"slug":"cve-2026-87595-google-chrome-server-side-request-forgery-in-mobile","title":"Google Chrome server-side request forgery in Mobile","severity":"critical","exploited":false,"published_at":"2026-09-09T01:17:17.437+00:00","url":"https://junglewise.ai/threats/cve-2026-87595-google-chrome-server-side-request-forgery-in-mobile"},{"cve":"CVE-2026-87544","cvss":9.8,"epss":0.0034,"slug":"cve-2026-87544-google-chrome-incorrect-authorization-in-extensions","title":"Google Chrome incorrect authorization in Extensions","severity":"critical","exploited":false,"published_at":"2026-09-09T01:17:11.92+00:00","url":"https://junglewise.ai/threats/cve-2026-87544-google-chrome-incorrect-authorization-in-extensions"}],"high":51,"name":"Google Chrome","rank":3,"slug":"chrome","score":509,"vendor":{"name":"Google","slug":"google"},"critical":34,"max_cvss":9.8,"max_epss":0.0314,"exploited":1,"vulnerabilities":227,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-87534","cvss":9.8,"epss":0.0029,"slug":"cve-2026-87534-google-chrome-missing-authorization-in-webview-on-android","title":"Google Chrome missing authorization in WebView on Android","severity":"critical","exploited":false,"published_at":"2026-09-09T01:17:10.823+00:00","url":"https://junglewise.ai/threats/cve-2026-87534-google-chrome-missing-authorization-in-webview-on-android"},{"cve":"CVE-2026-58822","cvss":9.8,"epss":0.0038,"slug":"cve-2026-58822-freetype-ftsmooth-memory-safety-issue-in-casting","title":"FreeType ftsmooth memory safety issue in casting","severity":"critical","exploited":false,"published_at":"2026-09-08T19:18:02.78+00:00","url":"https://junglewise.ai/threats/cve-2026-58822-freetype-ftsmooth-memory-safety-issue-in-casting"},{"cve":"CVE-2026-49921","cvss":9.8,"epss":0.0039,"slug":"cve-2026-49921-android-system-heap-buffer-overflow","title":"Android System heap buffer overflow","severity":"critical","exploited":false,"published_at":"2026-09-08T19:17:59.193+00:00","url":"https://junglewise.ai/threats/cve-2026-49921-android-system-heap-buffer-overflow"}],"high":59,"name":"Google Android","rank":4,"slug":"android","score":261,"vendor":{"name":"Google","slug":"google"},"critical":8,"max_cvss":9.8,"max_epss":0.0046,"exploited":0,"vulnerabilities":103,"url":"https://junglewise.ai/threats/technologies/android"},{"hub":true,"top":[{"cve":"CVE-2026-67643","cvss":9.8,"epss":0.0097,"slug":"cve-2026-67643-microsoft-sql-server-heap-based-buffer-overflow","title":"Microsoft SQL Server heap-based buffer overflow","severity":"critical","exploited":false,"published_at":"2026-09-08T18:18:24.53+00:00","url":"https://junglewise.ai/threats/cve-2026-67643-microsoft-sql-server-heap-based-buffer-overflow"},{"cve":"CVE-2026-67631","cvss":9.8,"epss":0.0097,"slug":"cve-2026-67631-microsoft-sql-server-heap-buffer-overflow","title":"Microsoft SQL Server heap buffer overflow","severity":"critical","exploited":false,"published_at":"2026-09-08T18:18:23.59+00:00","url":"https://junglewise.ai/threats/cve-2026-67631-microsoft-sql-server-heap-buffer-overflow"},{"cve":"CVE-2026-65669","cvss":9.6,"epss":0.0088,"slug":"cve-2026-65669-microsoft-sql-server-sql-injection-privilege-escalation","title":"Microsoft SQL Server SQL injection privilege escalation","severity":"critical","exploited":false,"published_at":"2026-09-08T18:18:14.893+00:00","url":"https://junglewise.ai/threats/cve-2026-65669-microsoft-sql-server-sql-injection-privilege-escalation"}],"high":31,"name":"Microsoft SQL Server","rank":5,"slug":"sql-server","score":147,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":5,"max_cvss":9.8,"max_epss":0.0169,"exploited":0,"vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/sql-server"},{"hub":true,"top":[{"cve":"CVE-2026-88869","cvss":9.3,"epss":0.0053,"slug":"cve-2026-88869-avideo-ad-server-stored-xss-in-log-php-label-parameter","title":"AVideo AD_Server stored XSS in log.php label parameter","severity":"critical","exploited":false,"published_at":"2026-09-10T14:17:14.637+00:00","url":"https://junglewise.ai/threats/cve-2026-88869-avideo-ad-server-stored-xss-in-log-php-label-parameter"},{"cve":"CVE-2026-89256","cvss":8.7,"epss":0.0037,"slug":"cve-2026-89256-avideo-bookmark-plugin-stored-cross-site-scripting-in-chapter","title":"AVideo Bookmark plugin stored cross-site scripting in chapter names","severity":"high","exploited":false,"published_at":"2026-09-11T12:16:56.003+00:00","url":"https://junglewise.ai/threats/cve-2026-89256-avideo-bookmark-plugin-stored-cross-site-scripting-in-chapter"},{"cve":"CVE-2026-89255","cvss":8.7,"epss":0.0037,"slug":"cve-2026-89255-avideo-logincontrol-stored-xss-in-pgp-public-key","title":"AVideo LoginControl stored XSS in PGP public key","severity":"high","exploited":false,"published_at":"2026-09-11T12:16:55.85+00:00","url":"https://junglewise.ai/threats/cve-2026-89255-avideo-logincontrol-stored-xss-in-pgp-public-key"}],"high":27,"name":"WWBN AVideo","rank":6,"slug":"avideo","score":120,"vendor":{"name":"WWBN","slug":"wwbn"},"critical":1,"max_cvss":9.3,"max_epss":0.006,"exploited":0,"vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/avideo"},{"hub":true,"top":[{"cve":"CVE-2026-61410","cvss":9.4,"epss":0.0085,"slug":"cve-2026-61410-dell-secure-connect-gateway-missing-authorization-remote-code","title":"Dell Secure Connect Gateway missing authorization remote code execution","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:33.853+00:00","url":"https://junglewise.ai/threats/cve-2026-61410-dell-secure-connect-gateway-missing-authorization-remote-code"},{"cve":"CVE-2026-80238","cvss":9.3,"epss":0.0019,"slug":"cve-2026-80238-dell-secure-connect-gateway-execution-with-unnecessary-privileges","title":"Dell Secure Connect Gateway execution with unnecessary privileges via Docker socket","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:39.293+00:00","url":"https://junglewise.ai/threats/cve-2026-80238-dell-secure-connect-gateway-execution-with-unnecessary-privileges"},{"cve":"CVE-2026-79645","cvss":8.2,"epss":0.0041,"slug":"cve-2026-79645-dell-secure-connect-gateway-missing-authentication-in-critical","title":"Dell Secure Connect Gateway missing authentication in critical function","severity":"high","exploited":false,"published_at":"2026-09-07T15:17:32.033+00:00","url":"https://junglewise.ai/threats/cve-2026-79645-dell-secure-connect-gateway-missing-authentication-in-critical"}],"high":17,"name":"Dell Secure Connect Gateway Appliance","rank":7,"slug":"secure-connect-gateway-appliance","score":100,"vendor":{"name":"Dell","slug":"dell"},"critical":2,"max_cvss":9.4,"max_epss":0.0473,"exploited":0,"vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-appliance"},{"hub":true,"top":[{"cve":"CVE-2026-61410","cvss":9.4,"epss":0.0085,"slug":"cve-2026-61410-dell-secure-connect-gateway-missing-authorization-remote-code","title":"Dell Secure Connect Gateway missing authorization remote code execution","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:33.853+00:00","url":"https://junglewise.ai/threats/cve-2026-61410-dell-secure-connect-gateway-missing-authorization-remote-code"},{"cve":"CVE-2026-80238","cvss":9.3,"epss":0.0019,"slug":"cve-2026-80238-dell-secure-connect-gateway-execution-with-unnecessary-privileges","title":"Dell Secure Connect Gateway execution with unnecessary privileges via Docker socket","severity":"critical","exploited":false,"published_at":"2026-09-07T13:20:39.293+00:00","url":"https://junglewise.ai/threats/cve-2026-80238-dell-secure-connect-gateway-execution-with-unnecessary-privileges"},{"cve":"CVE-2026-79645","cvss":8.2,"epss":0.0041,"slug":"cve-2026-79645-dell-secure-connect-gateway-missing-authentication-in-critical","title":"Dell Secure Connect Gateway missing authentication in critical function","severity":"high","exploited":false,"published_at":"2026-09-07T15:17:32.033+00:00","url":"https://junglewise.ai/threats/cve-2026-79645-dell-secure-connect-gateway-missing-authentication-in-critical"}],"high":17,"name":"Dell Secure Connect Gateway Application","rank":8,"slug":"secure-connect-gateway-application","score":100,"vendor":{"name":"Dell","slug":"dell"},"critical":2,"max_cvss":9.4,"max_epss":0.0473,"exploited":0,"vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-application"},{"hub":true,"top":[{"cve":"CVE-2026-87637","cvss":9.6,"epss":0.0046,"slug":"cve-2026-87637-google-chrome-use-after-free-in-extensions-on-mac","title":"Google Chrome use-after-free in Extensions on Mac","severity":"critical","exploited":false,"published_at":"2026-09-09T01:17:22.103+00:00","url":"https://junglewise.ai/threats/cve-2026-87637-google-chrome-use-after-free-in-extensions-on-mac"},{"cve":"CVE-2026-87607","cvss":9.6,"epss":0.0046,"slug":"cve-2026-87607-google-chrome-use-after-free-in-device-on-mac","title":"Google Chrome use-after-free in Device on Mac","severity":"critical","exploited":false,"published_at":"2026-09-09T01:17:18.763+00:00","url":"https://junglewise.ai/threats/cve-2026-87607-google-chrome-use-after-free-in-device-on-mac"},{"cve":"CVE-2026-87558","cvss":9.6,"epss":0.0046,"slug":"cve-2026-87558-google-chrome-use-after-free-in-payments-on-mac","title":"Google Chrome use after free in Payments on Mac","severity":"critical","exploited":false,"published_at":"2026-09-09T01:17:13.443+00:00","url":"https://junglewise.ai/threats/cve-2026-87558-google-chrome-use-after-free-in-payments-on-mac"}],"high":20,"name":"Apple macOS","rank":9,"slug":"macos-tahoe","score":100,"vendor":{"name":"Apple","slug":"apple"},"critical":4,"max_cvss":9.6,"max_epss":0.006,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-69826","cvss":8,"epss":0.0077,"slug":"cve-2026-69826-microsoft-windows-biometric-service-heap-buffer-overflow","title":"Microsoft Windows Biometric Service heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:54.37+00:00","url":"https://junglewise.ai/threats/cve-2026-69826-microsoft-windows-biometric-service-heap-buffer-overflow"},{"cve":"CVE-2026-69773","cvss":8,"epss":0.0077,"slug":"cve-2026-69773-microsoft-windows-biometric-service-heap-buffer-overflow","title":"Microsoft Windows Biometric Service heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:48.807+00:00","url":"https://junglewise.ai/threats/cve-2026-69773-microsoft-windows-biometric-service-heap-buffer-overflow"},{"cve":"CVE-2026-83988","cvss":7.8,"epss":0.0033,"slug":"cve-2026-83988-microsoft-windows-biometric-service-heap-buffer-overflow","title":"Microsoft Windows Biometric Service heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:21:09.343+00:00","url":"https://junglewise.ai/threats/cve-2026-83988-microsoft-windows-biometric-service-heap-buffer-overflow"}],"high":33,"name":"Microsoft Windows Biometric Service","rank":10,"slug":"windows-biometric-service","score":100,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":0,"max_cvss":8,"max_epss":0.0077,"exploited":0,"vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/windows-biometric-service"},{"hub":true,"top":[{"cve":"CVE-2026-81952","cvss":8.8,"epss":0.0082,"slug":"cve-2026-81952-microsoft-office-word-heap-buffer-overflow","title":"Microsoft Office Word heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:58.727+00:00","url":"https://junglewise.ai/threats/cve-2026-81952-microsoft-office-word-heap-buffer-overflow"},{"cve":"CVE-2026-80085","cvss":8.8,"epss":0.0082,"slug":"cve-2026-80085-microsoft-office-word-heap-buffer-overflow","title":"Microsoft Office Word heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:50.87+00:00","url":"https://junglewise.ai/threats/cve-2026-80085-microsoft-office-word-heap-buffer-overflow"},{"cve":"CVE-2026-80080","cvss":8.8,"epss":0.0082,"slug":"cve-2026-80080-microsoft-office-word-double-free-vulnerability","title":"Microsoft Office Word double free vulnerability","severity":"high","exploited":false,"published_at":"2026-09-08T18:20:50.233+00:00","url":"https://junglewise.ai/threats/cve-2026-80080-microsoft-office-word-double-free-vulnerability"}],"high":21,"name":"Microsoft Office Word","rank":11,"slug":"office-word","score":77,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":0,"max_cvss":8.8,"max_epss":0.0092,"exploited":0,"vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/office-word"},{"hub":true,"top":[{"cve":"CVE-2026-80172","cvss":9.8,"epss":0.0025,"slug":"cve-2026-80172-dell-secure-connect-gateway-insufficient-verification-of-data","title":"Dell Secure Connect Gateway insufficient verification of data authenticity","severity":"critical","exploited":false,"published_at":"2026-09-09T12:17:15.057+00:00","url":"https://junglewise.ai/threats/cve-2026-80172-dell-secure-connect-gateway-insufficient-verification-of-data"},{"cve":"CVE-2026-78491","cvss":8.2,"epss":0.0027,"slug":"cve-2026-78491-dell-secure-connect-gateway-improper-certificate-validation","title":"Dell Secure Connect Gateway improper certificate validation","severity":"high","exploited":false,"published_at":"2026-09-09T09:17:10.87+00:00","url":"https://junglewise.ai/threats/cve-2026-78491-dell-secure-connect-gateway-improper-certificate-validation"},{"cve":"CVE-2026-80132","cvss":8.1,"epss":0.0047,"slug":"cve-2026-80132-dell-secure-connect-gateway-missing-authentication-in-critical","title":"Dell Secure Connect Gateway missing authentication in critical function","severity":"high","exploited":false,"published_at":"2026-09-07T13:20:38.67+00:00","url":"https://junglewise.ai/threats/cve-2026-80132-dell-secure-connect-gateway-missing-authentication-in-critical"}],"high":14,"name":"Dell Secure Connect Gateway 5.0 Appliance","rank":12,"slug":"secure-connect-gateway-5-0-appliance","score":73,"vendor":{"name":"Dell","slug":"dell"},"critical":1,"max_cvss":9.8,"max_epss":0.0482,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-5-0-appliance"},{"hub":true,"top":[{"cve":"CVE-2026-80172","cvss":9.8,"epss":0.0025,"slug":"cve-2026-80172-dell-secure-connect-gateway-insufficient-verification-of-data","title":"Dell Secure Connect Gateway insufficient verification of data authenticity","severity":"critical","exploited":false,"published_at":"2026-09-09T12:17:15.057+00:00","url":"https://junglewise.ai/threats/cve-2026-80172-dell-secure-connect-gateway-insufficient-verification-of-data"},{"cve":"CVE-2026-78491","cvss":8.2,"epss":0.0027,"slug":"cve-2026-78491-dell-secure-connect-gateway-improper-certificate-validation","title":"Dell Secure Connect Gateway improper certificate validation","severity":"high","exploited":false,"published_at":"2026-09-09T09:17:10.87+00:00","url":"https://junglewise.ai/threats/cve-2026-78491-dell-secure-connect-gateway-improper-certificate-validation"},{"cve":"CVE-2026-80132","cvss":8.1,"epss":0.0047,"slug":"cve-2026-80132-dell-secure-connect-gateway-missing-authentication-in-critical","title":"Dell Secure Connect Gateway missing authentication in critical function","severity":"high","exploited":false,"published_at":"2026-09-07T13:20:38.67+00:00","url":"https://junglewise.ai/threats/cve-2026-80132-dell-secure-connect-gateway-missing-authentication-in-critical"}],"high":14,"name":"Dell Secure Connect Gateway 5.0 Application","rank":13,"slug":"secure-connect-gateway-5-0-application","score":73,"vendor":{"name":"Dell","slug":"dell"},"critical":1,"max_cvss":9.8,"max_epss":0.0482,"exploited":0,"vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/secure-connect-gateway-5-0-application"},{"hub":true,"top":[{"cve":"CVE-2026-81996","cvss":8.8,"epss":0.0024,"slug":"cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect","title":"Adobe Acrobat Reader privilege escalation via incorrect authorization","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.347+00:00","url":"https://junglewise.ai/threats/cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect"},{"cve":"CVE-2026-81994","cvss":8.2,"epss":0.006,"slug":"cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read","title":"Adobe Acrobat Reader prototype pollution arbitrary file read","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.223+00:00","url":"https://junglewise.ai/threats/cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read"},{"cve":"CVE-2026-81992","cvss":7.8,"epss":0.0034,"slug":"cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow","title":"Adobe Acrobat Reader heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:45.98+00:00","url":"https://junglewise.ai/threats/cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow"}],"high":20,"name":"Adobe Acrobat","rank":14,"slug":"acrobat","score":71,"vendor":{"name":"Adobe","slug":"adobe"},"critical":0,"max_cvss":8.8,"max_epss":0.006,"exploited":0,"vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/acrobat"},{"hub":true,"top":[{"cve":"CVE-2026-81996","cvss":8.8,"epss":0.0024,"slug":"cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect","title":"Adobe Acrobat Reader privilege escalation via incorrect authorization","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.347+00:00","url":"https://junglewise.ai/threats/cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect"},{"cve":"CVE-2026-81994","cvss":8.2,"epss":0.006,"slug":"cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read","title":"Adobe Acrobat Reader prototype pollution arbitrary file read","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.223+00:00","url":"https://junglewise.ai/threats/cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read"},{"cve":"CVE-2026-81992","cvss":7.8,"epss":0.0034,"slug":"cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow","title":"Adobe Acrobat Reader heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:45.98+00:00","url":"https://junglewise.ai/threats/cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow"}],"high":20,"name":"Adobe Acrobat DC","rank":15,"slug":"acrobat-dc","score":71,"vendor":{"name":"Adobe","slug":"adobe"},"critical":0,"max_cvss":8.8,"max_epss":0.006,"exploited":0,"vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/acrobat-dc"},{"hub":true,"top":[{"cve":"CVE-2026-81996","cvss":8.8,"epss":0.0024,"slug":"cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect","title":"Adobe Acrobat Reader privilege escalation via incorrect authorization","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.347+00:00","url":"https://junglewise.ai/threats/cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect"},{"cve":"CVE-2026-81994","cvss":8.2,"epss":0.006,"slug":"cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read","title":"Adobe Acrobat Reader prototype pollution arbitrary file read","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.223+00:00","url":"https://junglewise.ai/threats/cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read"},{"cve":"CVE-2026-81992","cvss":7.8,"epss":0.0034,"slug":"cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow","title":"Adobe Acrobat Reader heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:45.98+00:00","url":"https://junglewise.ai/threats/cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow"}],"high":20,"name":"Adobe Acrobat Reader","rank":16,"slug":"acrobat-reader","score":71,"vendor":{"name":"Adobe","slug":"adobe"},"critical":0,"max_cvss":8.8,"max_epss":0.006,"exploited":0,"vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/acrobat-reader"},{"hub":true,"top":[{"cve":"CVE-2026-81996","cvss":8.8,"epss":0.0024,"slug":"cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect","title":"Adobe Acrobat Reader privilege escalation via incorrect authorization","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.347+00:00","url":"https://junglewise.ai/threats/cve-2026-81996-adobe-acrobat-reader-privilege-escalation-via-incorrect"},{"cve":"CVE-2026-81994","cvss":8.2,"epss":0.006,"slug":"cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read","title":"Adobe Acrobat Reader prototype pollution arbitrary file read","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:46.223+00:00","url":"https://junglewise.ai/threats/cve-2026-81994-adobe-acrobat-reader-prototype-pollution-arbitrary-file-read"},{"cve":"CVE-2026-81992","cvss":7.8,"epss":0.0034,"slug":"cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow","title":"Adobe Acrobat Reader heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T21:18:45.98+00:00","url":"https://junglewise.ai/threats/cve-2026-81992-adobe-acrobat-reader-heap-based-buffer-overflow"}],"high":20,"name":"Adobe Acrobat Reader DC","rank":17,"slug":"acrobat-reader-dc","score":71,"vendor":{"name":"Adobe","slug":"adobe"},"critical":0,"max_cvss":8.8,"max_epss":0.006,"exploited":0,"vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/acrobat-reader-dc"},{"hub":true,"top":[{"cve":"CVE-2026-72979","cvss":9.8,"epss":0.0097,"slug":"cve-2026-72979-microsoft-windows-dhcp-server-use-after-free","title":"Microsoft Windows DHCP Server use-after-free","severity":"critical","exploited":false,"published_at":"2026-09-08T18:20:24.31+00:00","url":"https://junglewise.ai/threats/cve-2026-72979-microsoft-windows-dhcp-server-use-after-free"},{"cve":"CVE-2026-69845","cvss":9.8,"epss":0.0102,"slug":"cve-2026-69845-microsoft-windows-dhcp-server-heap-based-buffer-overflow","title":"Microsoft Windows DHCP Server heap-based buffer overflow","severity":"critical","exploited":false,"published_at":"2026-09-08T18:19:56.003+00:00","url":"https://junglewise.ai/threats/cve-2026-69845-microsoft-windows-dhcp-server-heap-based-buffer-overflow"},{"cve":"CVE-2026-69547","cvss":8.8,"epss":0.0091,"slug":"cve-2026-69547-microsoft-windows-dhcp-server-heap-buffer-overflow","title":"Microsoft Windows DHCP Server heap buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-08T18:19:23.107+00:00","url":"https://junglewise.ai/threats/cve-2026-69547-microsoft-windows-dhcp-server-heap-buffer-overflow"}],"high":15,"name":"Microsoft Windows DHCP Server","rank":18,"slug":"windows-dhcp-server","score":68,"vendor":{"name":"Microsoft","slug":"microsoft"},"critical":2,"max_cvss":9.8,"max_epss":0.0117,"exploited":0,"vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/windows-dhcp-server"},{"hub":true,"top":[{"cve":"CVE-2026-86738","cvss":8.7,"epss":0.0049,"slug":"cve-2026-86738-snipe-it-css-injection-in-custom-css-field","title":"Snipe-IT CSS injection in custom CSS field","severity":"high","exploited":false,"published_at":"2026-09-08T16:18:36.98+00:00","url":"https://junglewise.ai/threats/cve-2026-86738-snipe-it-css-injection-in-custom-css-field"},{"cve":"CVE-2026-86751","cvss":8.5,"epss":0.0037,"slug":"cve-2026-86751-snipe-it-markdown-image-injection-in-mail-notifications","title":"Snipe-IT markdown image injection in mail notifications","severity":"high","exploited":false,"published_at":"2026-09-09T14:17:24.17+00:00","url":"https://junglewise.ai/threats/cve-2026-86751-snipe-it-markdown-image-injection-in-mail-notifications"},{"cve":"CVE-2026-86741","cvss":8.5,"epss":0.0035,"slug":"cve-2026-86741-snipe-it-arbitrary-file-read-and-ssrf-via-category-eula","title":"Snipe-IT arbitrary file read and SSRF via category EULA","severity":"high","exploited":false,"published_at":"2026-09-09T14:17:22.68+00:00","url":"https://junglewise.ai/threats/cve-2026-86741-snipe-it-arbitrary-file-read-and-ssrf-via-category-eula"}],"high":10,"name":"Snipeitapp Snipe-It","rank":19,"slug":"snipe-it","score":63,"vendor":{"name":"Snipeitapp","slug":"snipeitapp"},"critical":0,"max_cvss":8.7,"max_epss":0.0058,"exploited":0,"vulnerabilities":43,"url":"https://junglewise.ai/threats/technologies/snipe-it"},{"hub":true,"top":[{"cve":"CVE-2026-82107","cvss":9.6,"epss":0.0054,"slug":"cve-2026-82107-ibm-datastage-authentication-bypass-and-information-disclosure","title":"IBM DataStage authentication bypass and information disclosure","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:04.22+00:00","url":"https://junglewise.ai/threats/cve-2026-82107-ibm-datastage-authentication-bypass-and-information-disclosure"},{"cve":"CVE-2026-82100","cvss":9.6,"epss":0.0062,"slug":"cve-2026-82100-ibm-datastage-path-traversal-denial-of-service","title":"IBM DataStage path traversal denial of service","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:04.09+00:00","url":"https://junglewise.ai/threats/cve-2026-82100-ibm-datastage-path-traversal-denial-of-service"},{"cve":"CVE-2026-80424","cvss":9.1,"epss":0.0051,"slug":"cve-2026-80424-ibm-datastage-path-traversal-in-archive-extraction","title":"IBM DataStage path traversal in archive extraction","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:01.163+00:00","url":"https://junglewise.ai/threats/cve-2026-80424-ibm-datastage-path-traversal-in-archive-extraction"}],"high":15,"name":"IBM Datastage On Cloud Pak For Data","rank":20,"slug":"datastage-on-cloud-pak-for-data","score":63,"vendor":{"name":"IBM","slug":"ibm"},"critical":3,"max_cvss":9.6,"max_epss":0.0081,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"hub":true,"top":[{"cve":"CVE-2026-89049","cvss":9.9,"epss":0.0066,"slug":"cve-2026-89049-aws-systems-manager-agent-ssrf-in-session-manager-port-forwarding","title":"A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts","severity":"critical","exploited":false,"published_at":"2026-09-10T19:17:42.373+00:00","url":"https://junglewise.ai/threats/cve-2026-89049-aws-systems-manager-agent-ssrf-in-session-manager-port-forwarding"},{"cve":"CVE-2026-85228","cvss":9.1,"epss":0.0054,"slug":"cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer","title":"An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms","severity":"critical","exploited":false,"published_at":"2026-09-10T17:17:06.437+00:00","url":"https://junglewise.ai/threats/cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer"},{"cve":"CVE-2026-84942","cvss":8.7,"epss":0.0054,"slug":"cve-2026-84942-opensearch-dashboards-stored-xss-via-vega-expression-function","title":"Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with d","severity":"high","exploited":false,"published_at":"2026-09-08T20:18:51.307+00:00","url":"https://junglewise.ai/threats/cve-2026-84942-opensearch-dashboards-stored-xss-via-vega-expression-function"}],"high":16,"name":"Amazon AWS","rank":21,"slug":"aws","score":60,"vendor":{"name":"Amazon","slug":"amazon"},"critical":2,"max_cvss":9.9,"max_epss":0.0066,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/aws"},{"hub":true,"top":[{"cve":"CVE-2026-88278","cvss":9.8,"epss":0.0048,"slug":"cve-2026-88278-geovision-gv-lpc2211-ws-security-token-replay-attack","title":"GeoVision GV-LPC2211 WS-Security token replay attack","severity":"critical","exploited":false,"published_at":"2026-09-10T09:17:04.787+00:00","url":"https://junglewise.ai/threats/cve-2026-88278-geovision-gv-lpc2211-ws-security-token-replay-attack"},{"cve":"CVE-2026-88285","cvss":9.4,"epss":0.0051,"slug":"cve-2026-88285-geovision-gv-lpc2211-unauthenticated-ptz-control-service-access","title":"GeoVision GV-LPC2211 unauthenticated PTZ control service access","severity":"critical","exploited":false,"published_at":"2026-09-10T09:17:05.563+00:00","url":"https://junglewise.ai/threats/cve-2026-88285-geovision-gv-lpc2211-unauthenticated-ptz-control-service-access"},{"cve":"CVE-2026-88277","cvss":8.8,"epss":0.0065,"slug":"cve-2026-88277-geovision-gv-lpc2211-command-injection-in-onvif-consumerreference","title":"GeoVision GV-LPC2211 command injection in ONVIF ConsumerReference","severity":"high","exploited":false,"published_at":"2026-09-10T09:17:04.673+00:00","url":"https://junglewise.ai/threats/cve-2026-88277-geovision-gv-lpc2211-command-injection-in-onvif-consumerreference"}],"high":12,"name":"Geovision GV-LPC2211","rank":22,"slug":"gv-lpc2211","score":57,"vendor":{"name":"Geovision","slug":"geovision"},"critical":2,"max_cvss":9.8,"max_epss":0.0071,"exploited":0,"vulnerabilities":23,"url":"https://junglewise.ai/threats/technologies/gv-lpc2211"},{"hub":true,"top":[{"cve":"CVE-2026-81204","cvss":9.8,"epss":0.0086,"slug":"cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction","title":"IBM Langflow OSS code injection in graph construction","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:01.58+00:00","url":"https://junglewise.ai/threats/cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction"},{"cve":"CVE-2026-79724","cvss":9.8,"epss":0.0067,"slug":"cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization","title":"IBM Langflow OS command injection via improper neutralization","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:00.53+00:00","url":"https://junglewise.ai/threats/cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization"},{"cve":"CVE-2026-85025","cvss":9.8,"epss":0.0061,"slug":"cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints","title":"IBM Langflow arbitrary code execution in MCP endpoints","severity":"critical","exploited":false,"published_at":"2026-09-10T21:17:51.99+00:00","url":"https://junglewise.ai/threats/cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints"}],"high":12,"name":"Langflow","rank":23,"slug":"langflow","score":57,"vendor":{"name":"Langflow","slug":"langflow"},"critical":3,"max_cvss":9.8,"max_epss":0.0086,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/langflow"},{"hub":true,"top":[{"cve":"CVE-2026-81204","cvss":9.8,"epss":0.0086,"slug":"cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction","title":"IBM Langflow OSS code injection in graph construction","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:01.58+00:00","url":"https://junglewise.ai/threats/cve-2026-81204-ibm-langflow-oss-code-injection-in-graph-construction"},{"cve":"CVE-2026-79724","cvss":9.8,"epss":0.0067,"slug":"cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization","title":"IBM Langflow OS command injection via improper neutralization","severity":"critical","exploited":false,"published_at":"2026-09-10T22:17:00.53+00:00","url":"https://junglewise.ai/threats/cve-2026-79724-ibm-langflow-os-command-injection-via-improper-neutralization"},{"cve":"CVE-2026-85025","cvss":9.8,"epss":0.0061,"slug":"cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints","title":"IBM Langflow arbitrary code execution in MCP endpoints","severity":"critical","exploited":false,"published_at":"2026-09-10T21:17:51.99+00:00","url":"https://junglewise.ai/threats/cve-2026-85025-ibm-langflow-arbitrary-code-execution-in-mcp-endpoints"}],"high":12,"name":"IBM Langflow","rank":24,"slug":"langflow-oss","score":57,"vendor":{"name":"IBM","slug":"ibm"},"critical":3,"max_cvss":9.8,"max_epss":0.0086,"exploited":0,"vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"hub":true,"top":[{"cvss":9.8,"slug":"knowns-header-injection-in-api-endpoint-allows-arbitrary-filesystem-688e00ce","title":"Knowns header injection in API endpoint allows arbitrary filesystem access","severity":"critical","exploited":false,"published_at":"2026-09-10T18:31:45+00:00","url":"https://junglewise.ai/threats/knowns-header-injection-in-api-endpoint-allows-arbitrary-filesystem-688e00ce"},{"cve":"CVE-2026-88899","cvss":9.8,"epss":0.0081,"slug":"cve-2026-88899-knowns-path-traversal-in-api-opencode-proxy-endpoint","title":"Knowns path traversal in /api/opencode proxy endpoint","severity":"critical","exploited":false,"published_at":"2026-09-10T16:18:12.12+00:00","url":"https://junglewise.ai/threats/cve-2026-88899-knowns-path-traversal-in-api-opencode-proxy-endpoint"},{"cve":"CVE-2026-86543","cvss":9.8,"epss":0.0086,"slug":"cve-2026-86543-knowns-management-api-authentication-bypass","title":"knowns management API authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-07T23:16:54.16+00:00","url":"https://junglewise.ai/threats/cve-2026-86543-knowns-management-api-authentication-bypass"}],"high":10,"name":"Knowns-Dev Knowns","rank":25,"slug":"knowns","score":56,"vendor":{"name":"Knowns-Dev","slug":"knowns-dev"},"critical":4,"max_cvss":9.8,"max_epss":0.0108,"exploited":0,"vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/knowns"}],"previous":{"key":"2026-08-31","top":"Linux Kernel","period":{"end":"2026-09-06","start":"2026-08-31"},"totals":{"high":771,"critical":294,"exploited":7,"technologies":1040,"vulnerabilities":2379},"url":"https://junglewise.ai/threats/weekly/2026-08-31"},"next":{"key":"2026-09-14","top":"Linux Kernel","period":{"end":"2026-09-20","start":"2026-09-14"},"totals":{"high":1946,"critical":468,"exploited":4,"technologies":1697,"vulnerabilities":4840},"url":"https://junglewise.ai/threats/weekly/2026-09-14"}}