Weekly report
Most vulnerable technologies: week of 14 to 20 September 2026 (week 38)
Final report, published . It does not change.
In the week of 14 to 20 September 2026, Junglewise Threat Intelligence recorded 4,840 new vulnerabilities: 468 critical, 1,946 high and 4 exploited in the wild. The most vulnerable technology was Linux Kernel, with 867 vulnerabilities (32 critical), followed by Apple macOS (221) and Apple macOS Golden Gate (172).
- New vulnerabilities
- 4,840
- Critical
- 468
- Exploited in the wild
- 4
- Technologies affected
- 1,697
Ranking
Most affected vendors
- 1.Oracle592 vulnerabilities, 83 critical, 0 exploited
- 2.Linux867 vulnerabilities, 32 critical, 0 exploited
- 3.Apple252 vulnerabilities, 8 critical, 0 exploited
- 4.Google151 vulnerabilities, 13 critical, 1 exploited
- 5.Cisco83 vulnerabilities, 29 critical, 2 exploited
- 6.Mozilla77 vulnerabilities, 21 critical, 0 exploited
- 7.IBM95 vulnerabilities, 5 critical, 0 exploited
- 8.Go74 vulnerabilities, 5 critical, 0 exploited
- 9.Pip56 vulnerabilities, 11 critical, 0 exploited
- 10.Npm55 vulnerabilities, 7 critical, 0 exploited
Most severe vulnerabilities
- CVE-2026-76460: A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to…criticalexploited in the wildCVSS 10EPSS 14.0%
- CVE-2026-76461: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an…criticalexploited in the wildCVSS 9.8EPSS 28.3%
- CVE-2026-58704: In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote…criticalexploited in the wildCVSS 8.8EPSS 0.6%
- CVE-2026-87886: Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin…criticalexploited in the wildCVSS 7.8EPSS 0.2%
- CVE-2026-53710: MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the…criticalCVSS 10EPSS 1.1%
- CVE-2026-92937: vm2 sandbox escape in Promise rejection handlingcriticalCVSS 10EPSS 1.0%
- CVE-2026-94003: A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file…criticalCVSS 10EPSS 1.0%
- CVE-2026-94089: A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file…criticalCVSS 10EPSS 1.0%
- CVE-2026-70200: Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized…criticalCVSS 10EPSS 0.9%
- CVE-2026-69843: Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.criticalCVSS 10EPSS 0.9%
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
Technologies are ranked by a score: 10 points for each vulnerability exploited in the wild, 5 for each critical, 2 for each high and 1 for every vulnerability. A vulnerability counts once for every technology it affects, so one advisory can appear under several products.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/weekly/2026-09-14.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Most vulnerable technologies: week of 14 to 20 September 2026 (week 38)", https://junglewise.ai/threats/weekly/2026-09-14, 26 September 2026.