Junglewise

Weekly report

Most vulnerable technologies: week of 14 to 20 September 2026 (week 38)

Final report, published . It does not change.

In the week of 14 to 20 September 2026, Junglewise Threat Intelligence recorded 4,840 new vulnerabilities: 468 critical, 1,946 high and 4 exploited in the wild. The most vulnerable technology was Linux Kernel, with 867 vulnerabilities (32 critical), followed by Apple macOS (221) and Apple macOS Golden Gate (172).

New vulnerabilities
4,840
Critical
468
Exploited in the wild
4
Technologies affected
1,697

Ranking

Technologies ranked by exploited, critical and high severity vulnerabilities
#TechnologyVulnsCriticalHighExploitedMax CVSSMost severe
1Linux Kernel
Linux
8673227909.8
2Apple macOS
Apple
221872010
3Apple macOS Golden Gate
Apple
172854010
4Oracle Hyperion Financial Management
Oracle
801366010
5Mozilla Thunderbird
Mozilla
76214509.8
6Mozilla Firefox
Mozilla
72194309.8
7Apple iPadOS
Apple
13953709.8
8Google Android
Google
9754419.8
9Mozilla Firefox ESR
Mozilla
64124309.6
10Apple visionOS
Apple
9752509.8
11Google Chrome
Google
57102409.6
12Apple watchOS
Apple
8252109.8
13Npm Vm2
Npm
34207010
14Apple tvOS
Apple
7842209.8
15Oracle E-Business Suite
Oracle
4213909.8
16Cisco Identity Services Engine
Cisco
38125110
17Apple Iphone Os
Apple
6411909.1
18Oracle WebCenter Portal
Oracle
24101409.9
19Oracle Business Intelligence Enterprise Edition
Oracle
2922709.9
20Oracle Siebel CRM
Oracle
2742109.1
21Arista EOS
Arista
41410010
22Oracle Commerce Experience Manager
Oracle
2602408.2
23Oracle Access Manager
Oracle
15104010
24Oracle Commerce Guided Search
Oracle
2502308.2
25Oracle BI Publisher
Oracle
2121909.8

Most affected vendors

  1. 1.Oracle592 vulnerabilities, 83 critical, 0 exploited
  2. 2.Linux867 vulnerabilities, 32 critical, 0 exploited
  3. 3.Apple252 vulnerabilities, 8 critical, 0 exploited
  4. 4.Google151 vulnerabilities, 13 critical, 1 exploited
  5. 5.Cisco83 vulnerabilities, 29 critical, 2 exploited
  6. 6.Mozilla77 vulnerabilities, 21 critical, 0 exploited
  7. 7.IBM95 vulnerabilities, 5 critical, 0 exploited
  8. 8.Go74 vulnerabilities, 5 critical, 0 exploited
  9. 9.Pip56 vulnerabilities, 11 critical, 0 exploited
  10. 10.Npm55 vulnerabilities, 7 critical, 0 exploited

Most severe vulnerabilities

How this is built

Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.

Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.

The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.

Use this data

The same data is at https://junglewise.ai/threats/weekly/2026-09-14.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.

Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 14 to 20 September 2026 (week 38)", https://junglewise.ai/threats/weekly/2026-09-14, 26 September 2026.