{"schema_version":1,"title":"Most vulnerable technologies: week of 14 to 20 September 2026 (week 38)","summary":"In the week of 14 to 20 September 2026, Junglewise Threat Intelligence recorded 4,840 new vulnerabilities: 468 critical, 1,946 high and 4 exploited in the wild. The most vulnerable technology was Linux Kernel, with 867 vulnerabilities (32 critical), followed by Apple macOS (221) and Apple macOS Golden Gate (172).","url":"https://junglewise.ai/threats/weekly/2026-09-14","json_url":"https://junglewise.ai/threats/weekly/2026-09-14.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/weekly/2026-09-14","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","method":"Technologies are ranked by 10 points per vulnerability exploited in the wild, 5 per critical, 2 per high and 1 per vulnerability, over vulnerabilities published in the period (UTC). A vulnerability counts for every technology it affects.","kind":"week","period":{"end":"2026-09-20","start":"2026-09-14"},"totals":{"high":1946,"critical":468,"exploited":4,"technologies":1697,"vulnerabilities":4840},"notable":[{"cve":"CVE-2026-76460","cvss":10,"epss":0.1403,"slug":"cve-2026-76460-cisco-identity-services-engine-incorrect-privileged-api-use","title":"A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.","severity":"critical","exploited":true,"published_at":"2026-09-16T21:17:21.43+00:00","url":"https://junglewise.ai/threats/cve-2026-76460-cisco-identity-services-engine-incorrect-privileged-api-use"},{"cve":"CVE-2026-76461","cvss":9.8,"epss":0.2827,"slug":"cve-2026-76461-cisco-secure-email-gateway-sql-injection","title":"A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacke","severity":"critical","exploited":true,"published_at":"2026-09-14T17:17:51.113+00:00","url":"https://junglewise.ai/threats/cve-2026-76461-cisco-secure-email-gateway-sql-injection"},{"cve":"CVE-2026-58704","cvss":8.8,"epss":0.0059,"slug":"cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem","title":"In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) esc","severity":"critical","exploited":true,"published_at":"2026-09-15T19:17:32.297+00:00","url":"https://junglewise.ai/threats/cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem"},{"cve":"CVE-2026-87886","cvss":7.8,"epss":0.0023,"slug":"cve-2026-87886-acronis-backup-privilege-escalation-in-cpanel-whm-and-plesk","title":"Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Li","severity":"critical","exploited":true,"published_at":"2026-09-17T23:18:53.763+00:00","url":"https://junglewise.ai/threats/cve-2026-87886-acronis-backup-privilege-escalation-in-cpanel-whm-and-plesk"},{"cve":"CVE-2026-53710","cvss":10,"epss":0.0114,"slug":"cve-2026-53710-ibm-mcp-contextforge-gateway-restrictedpython-sandbox-bypass-via","title":"MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp","severity":"critical","exploited":false,"published_at":"2026-09-15T17:17:19.117+00:00","url":"https://junglewise.ai/threats/cve-2026-53710-ibm-mcp-contextforge-gateway-restrictedpython-sandbox-bypass-via"},{"cve":"CVE-2026-92937","cvss":10,"epss":0.0103,"slug":"cve-2026-92937-vm2-sandbox-escape-in-promise-rejection-handling","title":"vm2 sandbox escape in Promise rejection handling","severity":"critical","exploited":false,"published_at":"2026-09-17T14:17:58.517+00:00","url":"https://junglewise.ai/threats/cve-2026-92937-vm2-sandbox-escape-in-promise-rejection-handling"},{"cve":"CVE-2026-94003","cvss":10,"epss":0.0102,"slug":"cve-2026-94003-a-vulnerability-has-been-found-in-comfast-cf-n1-s-2-6-0-1","title":"A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config o","severity":"critical","exploited":false,"published_at":"2026-09-20T12:17:05.403+00:00","url":"https://junglewise.ai/threats/cve-2026-94003-a-vulnerability-has-been-found-in-comfast-cf-n1-s-2-6-0-1"},{"cve":"CVE-2026-94089","cvss":10,"epss":0.0098,"slug":"cve-2026-94089-a-vulnerability-was-determined-in-d-link-dir-868l-2-01b05-this","title":"A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of t","severity":"critical","exploited":false,"published_at":"2026-09-20T21:16:55.78+00:00","url":"https://junglewise.ai/threats/cve-2026-94089-a-vulnerability-was-determined-in-d-link-dir-868l-2-01b05-this"},{"cve":"CVE-2026-70200","cvss":10,"epss":0.0093,"slug":"cve-2026-70200-improper-limitation-of-a-pathname-to-a-restricted-directory-path","title":"Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevat","severity":"critical","exploited":false,"published_at":"2026-09-17T23:18:36.113+00:00","url":"https://junglewise.ai/threats/cve-2026-70200-improper-limitation-of-a-pathname-to-a-restricted-directory-path"},{"cve":"CVE-2026-69843","cvss":10,"epss":0.0092,"slug":"cve-2026-69843-authentication-bypass-by-spoofing-in-microsoft-fabric-allows-an","title":"Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.","severity":"critical","exploited":false,"published_at":"2026-09-18T00:17:24.923+00:00","url":"https://junglewise.ai/threats/cve-2026-69843-authentication-bypass-by-spoofing-in-microsoft-fabric-allows-an"}],"vendors":[{"hub":true,"high":463,"name":"Oracle","rank":1,"slug":"oracle","critical":83,"exploited":0,"vulnerabilities":592,"url":"https://junglewise.ai/threats/vendors/oracle"},{"hub":true,"high":279,"name":"Linux","rank":2,"slug":"linux","critical":32,"exploited":0,"vulnerabilities":867,"url":"https://junglewise.ai/threats/vendors/linux"},{"hub":true,"high":82,"name":"Apple","rank":3,"slug":"apple","critical":8,"exploited":0,"vulnerabilities":252,"url":"https://junglewise.ai/threats/vendors/apple"},{"hub":true,"high":69,"name":"Google","rank":4,"slug":"google","critical":13,"exploited":1,"vulnerabilities":151,"url":"https://junglewise.ai/threats/vendors/google"},{"hub":true,"high":26,"name":"Cisco","rank":5,"slug":"cisco","critical":29,"exploited":2,"vulnerabilities":83,"url":"https://junglewise.ai/threats/vendors/cisco"},{"hub":true,"high":46,"name":"Mozilla","rank":6,"slug":"mozilla","critical":21,"exploited":0,"vulnerabilities":77,"url":"https://junglewise.ai/threats/vendors/mozilla"},{"hub":true,"high":37,"name":"IBM","rank":7,"slug":"ibm","critical":5,"exploited":0,"vulnerabilities":95,"url":"https://junglewise.ai/threats/vendors/ibm"},{"hub":true,"high":31,"name":"Go","rank":8,"slug":"go","critical":5,"exploited":0,"vulnerabilities":74,"url":"https://junglewise.ai/threats/vendors/go"},{"hub":true,"high":20,"name":"Pip","rank":9,"slug":"pip","critical":11,"exploited":0,"vulnerabilities":56,"url":"https://junglewise.ai/threats/vendors/pip"},{"hub":true,"high":26,"name":"Npm","rank":10,"slug":"npm","critical":7,"exploited":0,"vulnerabilities":55,"url":"https://junglewise.ai/threats/vendors/npm"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"hub":true,"top":[{"cve":"CVE-2026-92489","cvss":9.8,"epss":0.0067,"slug":"cve-2026-92489-linux-kernel-double-free-in-xfrm-dev-direct-output","title":"Linux kernel double-free in xfrm_dev_direct_output","severity":"critical","exploited":false,"published_at":"2026-09-17T17:17:51.007+00:00","url":"https://junglewise.ai/threats/cve-2026-92489-linux-kernel-double-free-in-xfrm-dev-direct-output"},{"cve":"CVE-2026-90235","cvss":9.8,"epss":0.0067,"slug":"cve-2026-90235-linux-kernel-sunrpc-xprtsock-race-condition-in-socket-callback","title":"Linux kernel SUNRPC xprtsock race condition in socket callback handling","severity":"critical","exploited":false,"published_at":"2026-09-17T17:17:19.4+00:00","url":"https://junglewise.ai/threats/cve-2026-90235-linux-kernel-sunrpc-xprtsock-race-condition-in-socket-callback"},{"cve":"CVE-2026-90173","cvss":9.8,"epss":0.0055,"slug":"cve-2026-90173-linux-kernel-smbdirect-use-after-free-in-completion-queue-cleanup","title":"Linux kernel smbdirect use-after-free in completion queue cleanup","severity":"critical","exploited":false,"published_at":"2026-09-17T17:17:10.953+00:00","url":"https://junglewise.ai/threats/cve-2026-90173-linux-kernel-smbdirect-use-after-free-in-completion-queue-cleanup"}],"high":279,"name":"Linux Kernel","rank":1,"slug":"kernel","score":1585,"vendor":{"name":"Linux","slug":"linux"},"critical":32,"max_cvss":9.8,"max_epss":0.0087,"exploited":0,"vulnerabilities":867,"url":"https://junglewise.ai/threats/technologies/kernel"},{"hub":true,"top":[{"cve":"CVE-2026-65381","cvss":10,"epss":0.0035,"slug":"cve-2026-65381-apple-macos-sandbox-escape-in-entitlement-verification","title":"Apple macOS sandbox escape in entitlement verification","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:22.46+00:00","url":"https://junglewise.ai/threats/cve-2026-65381-apple-macos-sandbox-escape-in-entitlement-verification"},{"cve":"CVE-2026-84609","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation","title":"Apple iOS APFS permissions bypass in path validation","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation"},{"cve":"CVE-2026-84561","cvss":9.8,"epss":0.0068,"slug":"cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in","title":"Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS double free in memory management","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:32.173+00:00","url":"https://junglewise.ai/threats/cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in"}],"high":72,"name":"Apple macOS","rank":2,"slug":"macos-tahoe","score":405,"vendor":{"name":"Apple","slug":"apple"},"critical":8,"max_cvss":10,"max_epss":0.0108,"exploited":0,"vulnerabilities":221,"url":"https://junglewise.ai/threats/technologies/macos-tahoe"},{"hub":true,"top":[{"cve":"CVE-2026-65381","cvss":10,"epss":0.0035,"slug":"cve-2026-65381-apple-macos-sandbox-escape-in-entitlement-verification","title":"Apple macOS sandbox escape in entitlement verification","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:22.46+00:00","url":"https://junglewise.ai/threats/cve-2026-65381-apple-macos-sandbox-escape-in-entitlement-verification"},{"cve":"CVE-2026-84609","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation","title":"Apple iOS APFS permissions bypass in path validation","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation"},{"cve":"CVE-2026-84561","cvss":9.8,"epss":0.0068,"slug":"cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in","title":"Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS double free in memory management","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:32.173+00:00","url":"https://junglewise.ai/threats/cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in"}],"high":54,"name":"Apple macOS Golden Gate","rank":3,"slug":"macos-golden-gate","score":320,"vendor":{"name":"Apple","slug":"apple"},"critical":8,"max_cvss":10,"max_epss":0.0108,"exploited":0,"vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/macos-golden-gate"},{"hub":true,"top":[{"cve":"CVE-2026-87230","cvss":10,"epss":0.0043,"slug":"cve-2026-87230-oracle-hyperion-financial-management-authentication-bypass","title":"Oracle Hyperion Financial Management authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-15T20:19:11.513+00:00","url":"https://junglewise.ai/threats/cve-2026-87230-oracle-hyperion-financial-management-authentication-bypass"},{"cve":"CVE-2026-87172","cvss":9.9,"epss":0.0043,"slug":"cve-2026-87172-oracle-hyperion-financial-management-authentication-bypass-in","title":"Oracle Hyperion Financial Management authentication bypass in Security component","severity":"critical","exploited":false,"published_at":"2026-09-15T20:19:04.97+00:00","url":"https://junglewise.ai/threats/cve-2026-87172-oracle-hyperion-financial-management-authentication-bypass-in"},{"cve":"CVE-2026-87188","cvss":9.8,"epss":0.0051,"slug":"cve-2026-87188-oracle-hyperion-financial-management-authentication-bypass","title":"Oracle Hyperion Financial Management authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-15T20:19:06.727+00:00","url":"https://junglewise.ai/threats/cve-2026-87188-oracle-hyperion-financial-management-authentication-bypass"}],"high":66,"name":"Oracle Hyperion Financial Management","rank":4,"slug":"hyperion-financial-management","score":277,"vendor":{"name":"Oracle","slug":"oracle"},"critical":13,"max_cvss":10,"max_epss":0.0059,"exploited":0,"vulnerabilities":80,"url":"https://junglewise.ai/threats/technologies/hyperion-financial-management"},{"hub":true,"top":[{"cve":"CVE-2026-92238","cvss":9.8,"epss":0.0054,"slug":"cve-2026-92238-mozilla-thunderbird-mail-header-parsing-ambiguity","title":"Mozilla Thunderbird mail header parsing ambiguity","severity":"critical","exploited":false,"published_at":"2026-09-15T20:19:41.477+00:00","url":"https://junglewise.ai/threats/cve-2026-92238-mozilla-thunderbird-mail-header-parsing-ambiguity"},{"cve":"CVE-2026-92066","cvss":9.8,"epss":0.0059,"slug":"cve-2026-92066-mozilla-firefox-sandbox-escape-in-profile-backup","title":"Mozilla Firefox sandbox escape in Profile Backup","severity":"critical","exploited":false,"published_at":"2026-09-15T13:17:01.283+00:00","url":"https://junglewise.ai/threats/cve-2026-92066-mozilla-firefox-sandbox-escape-in-profile-backup"},{"cve":"CVE-2026-92061","cvss":9.8,"epss":0.0059,"slug":"cve-2026-92061-mozilla-firefox-incorrect-boundary-conditions-in-process","title":"Mozilla Firefox incorrect boundary conditions in process sandboxing","severity":"critical","exploited":false,"published_at":"2026-09-15T13:17:00.653+00:00","url":"https://junglewise.ai/threats/cve-2026-92061-mozilla-firefox-incorrect-boundary-conditions-in-process"}],"high":45,"name":"Mozilla Thunderbird","rank":5,"slug":"thunderbird","score":271,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":21,"max_cvss":9.8,"max_epss":0.0063,"exploited":0,"vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/thunderbird"},{"hub":true,"top":[{"cve":"CVE-2026-92066","cvss":9.8,"epss":0.0059,"slug":"cve-2026-92066-mozilla-firefox-sandbox-escape-in-profile-backup","title":"Mozilla Firefox sandbox escape in Profile Backup","severity":"critical","exploited":false,"published_at":"2026-09-15T13:17:01.283+00:00","url":"https://junglewise.ai/threats/cve-2026-92066-mozilla-firefox-sandbox-escape-in-profile-backup"},{"cve":"CVE-2026-92061","cvss":9.8,"epss":0.0059,"slug":"cve-2026-92061-mozilla-firefox-incorrect-boundary-conditions-in-process","title":"Mozilla Firefox incorrect boundary conditions in process sandboxing","severity":"critical","exploited":false,"published_at":"2026-09-15T13:17:00.653+00:00","url":"https://junglewise.ai/threats/cve-2026-92061-mozilla-firefox-incorrect-boundary-conditions-in-process"},{"cve":"CVE-2026-92037","cvss":9.8,"epss":0.0059,"slug":"cve-2026-92037-mozilla-firefox-incorrect-boundary-conditions-in-dom-animation","title":"Mozilla Firefox incorrect boundary conditions in DOM Animation component","severity":"critical","exploited":false,"published_at":"2026-09-15T13:16:55.067+00:00","url":"https://junglewise.ai/threats/cve-2026-92037-mozilla-firefox-incorrect-boundary-conditions-in-dom-animation"}],"high":43,"name":"Mozilla Firefox","rank":6,"slug":"firefox","score":253,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":19,"max_cvss":9.8,"max_epss":0.0059,"exploited":0,"vulnerabilities":72,"url":"https://junglewise.ai/threats/technologies/firefox"},{"hub":true,"top":[{"cve":"CVE-2026-84609","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation","title":"Apple iOS APFS permissions bypass in path validation","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation"},{"cve":"CVE-2026-84561","cvss":9.8,"epss":0.0068,"slug":"cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in","title":"Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS double free in memory management","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:32.173+00:00","url":"https://junglewise.ai/threats/cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in"},{"cve":"CVE-2026-65414","cvss":9.8,"epss":0.0108,"slug":"cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework","title":"Apple iOS and iPadOS out-of-bounds write in Accelerate Framework","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:25.057+00:00","url":"https://junglewise.ai/threats/cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework"}],"high":37,"name":"Apple iPadOS","rank":7,"slug":"ipados","score":238,"vendor":{"name":"Apple","slug":"apple"},"critical":5,"max_cvss":9.8,"max_epss":0.0108,"exploited":0,"vulnerabilities":139,"url":"https://junglewise.ai/threats/technologies/ipados"},{"hub":true,"top":[{"cve":"CVE-2026-58704","cvss":8.8,"epss":0.0059,"slug":"cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem","title":"In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) esc","severity":"critical","exploited":true,"published_at":"2026-09-15T19:17:32.297+00:00","url":"https://junglewise.ai/threats/cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem"},{"cve":"CVE-2026-56960","cvss":9.8,"epss":0.004,"slug":"cve-2026-56960-google-pixel-use-after-free-in-kernel","title":"Google Pixel use-after-free in kernel","severity":"critical","exploited":false,"published_at":"2026-09-15T19:17:28.76+00:00","url":"https://junglewise.ai/threats/cve-2026-56960-google-pixel-use-after-free-in-kernel"},{"cve":"CVE-2026-55366","cvss":9.8,"epss":0.0046,"slug":"cve-2026-55366-google-pixel-ip-multimedia-subsystem-authentication-bypass","title":"Google Pixel IP Multimedia Subsystem authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-15T19:17:22.227+00:00","url":"https://junglewise.ai/threats/cve-2026-55366-google-pixel-ip-multimedia-subsystem-authentication-bypass"}],"high":44,"name":"Google Android","rank":8,"slug":"android","score":220,"vendor":{"name":"Google","slug":"google"},"critical":5,"max_cvss":9.8,"max_epss":0.0059,"exploited":1,"vulnerabilities":97,"url":"https://junglewise.ai/threats/technologies/android"},{"hub":true,"top":[{"cve":"CVE-2026-92071","cvss":9.6,"epss":0.0048,"slug":"cve-2026-92071-mozilla-firefox-sandbox-escape-in-widget-win32-component","title":"Mozilla Firefox sandbox escape in Widget: Win32 component","severity":"critical","exploited":false,"published_at":"2026-09-15T13:17:01.86+00:00","url":"https://junglewise.ai/threats/cve-2026-92071-mozilla-firefox-sandbox-escape-in-widget-win32-component"},{"cve":"CVE-2026-92045","cvss":9.6,"epss":0.0048,"slug":"cve-2026-92045-mozilla-firefox-sandbox-escape-in-webrtc-due-to-incorrect","title":"Mozilla Firefox sandbox escape in WebRTC due to incorrect boundary conditions","severity":"critical","exploited":false,"published_at":"2026-09-15T13:16:55.973+00:00","url":"https://junglewise.ai/threats/cve-2026-92045-mozilla-firefox-sandbox-escape-in-webrtc-due-to-incorrect"},{"cve":"CVE-2026-92035","cvss":9.6,"epss":0.0048,"slug":"cve-2026-92035-mozilla-firefox-sandbox-escape-in-graphics-component","title":"Mozilla Firefox sandbox escape in Graphics component","severity":"critical","exploited":false,"published_at":"2026-09-15T13:16:54.843+00:00","url":"https://junglewise.ai/threats/cve-2026-92035-mozilla-firefox-sandbox-escape-in-graphics-component"}],"high":43,"name":"Mozilla Firefox ESR","rank":9,"slug":"firefox-esr","score":210,"vendor":{"name":"Mozilla","slug":"mozilla"},"critical":12,"max_cvss":9.6,"max_epss":0.005,"exploited":0,"vulnerabilities":64,"url":"https://junglewise.ai/threats/technologies/firefox-esr"},{"hub":true,"top":[{"cve":"CVE-2026-84609","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation","title":"Apple iOS APFS permissions bypass in path validation","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation"},{"cve":"CVE-2026-84561","cvss":9.8,"epss":0.0068,"slug":"cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in","title":"Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS double free in memory management","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:32.173+00:00","url":"https://junglewise.ai/threats/cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in"},{"cve":"CVE-2026-65414","cvss":9.8,"epss":0.0108,"slug":"cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework","title":"Apple iOS and iPadOS out-of-bounds write in Accelerate Framework","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:25.057+00:00","url":"https://junglewise.ai/threats/cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework"}],"high":25,"name":"Apple visionOS","rank":10,"slug":"visionos","score":172,"vendor":{"name":"Apple","slug":"apple"},"critical":5,"max_cvss":9.8,"max_epss":0.0108,"exploited":0,"vulnerabilities":97,"url":"https://junglewise.ai/threats/technologies/visionos"},{"hub":true,"top":[{"cve":"CVE-2026-93374","cvss":9.6,"epss":0.0041,"slug":"cve-2026-93374-google-chrome-use-after-free-in-dawn-on-android","title":"Google Chrome use-after-free in Dawn on Android","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.42+00:00","url":"https://junglewise.ai/threats/cve-2026-93374-google-chrome-use-after-free-in-dawn-on-android"},{"cve":"CVE-2026-93373","cvss":9.6,"epss":0.0034,"slug":"cve-2026-93373-google-chrome-use-after-free-in-extensions-sandbox-escape","title":"Google Chrome use-after-free in Extensions sandbox escape","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.29+00:00","url":"https://junglewise.ai/threats/cve-2026-93373-google-chrome-use-after-free-in-extensions-sandbox-escape"},{"cve":"CVE-2026-93372","cvss":9.6,"epss":0.0045,"slug":"cve-2026-93372-google-chrome-buffer-overflow-in-webgl","title":"Google Chrome buffer overflow in WebGL","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.18+00:00","url":"https://junglewise.ai/threats/cve-2026-93372-google-chrome-buffer-overflow-in-webgl"}],"high":24,"name":"Google Chrome","rank":11,"slug":"chrome","score":155,"vendor":{"name":"Google","slug":"google"},"critical":10,"max_cvss":9.6,"max_epss":0.0045,"exploited":0,"vulnerabilities":57,"url":"https://junglewise.ai/threats/technologies/chrome"},{"hub":true,"top":[{"cve":"CVE-2026-84609","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation","title":"Apple iOS APFS permissions bypass in path validation","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation"},{"cve":"CVE-2026-84561","cvss":9.8,"epss":0.0068,"slug":"cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in","title":"Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS double free in memory management","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:32.173+00:00","url":"https://junglewise.ai/threats/cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in"},{"cve":"CVE-2026-65414","cvss":9.8,"epss":0.0108,"slug":"cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework","title":"Apple iOS and iPadOS out-of-bounds write in Accelerate Framework","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:25.057+00:00","url":"https://junglewise.ai/threats/cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework"}],"high":21,"name":"Apple watchOS","rank":12,"slug":"watchos","score":149,"vendor":{"name":"Apple","slug":"apple"},"critical":5,"max_cvss":9.8,"max_epss":0.0108,"exploited":0,"vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/watchos"},{"hub":true,"top":[{"cve":"CVE-2026-93606","cvss":10,"epss":0.0071,"slug":"cve-2026-93606-vm2-sandbox-escape-via-promise-symbol-species-hijack","title":"vm2 sandbox escape via Promise Symbol.species hijack","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.5+00:00","url":"https://junglewise.ai/threats/cve-2026-93606-vm2-sandbox-escape-via-promise-symbol-species-hijack"},{"cve":"CVE-2026-93605","cvss":10,"epss":0.0073,"slug":"cve-2026-93605-vm2-nodevm-sandbox-escape-via-child-process-denylist-omission","title":"vm2 NodeVM sandbox escape via child_process denylist omission","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.34+00:00","url":"https://junglewise.ai/threats/cve-2026-93605-vm2-nodevm-sandbox-escape-via-child-process-denylist-omission"},{"cve":"CVE-2026-93603","cvss":10,"epss":0.0073,"slug":"cve-2026-93603-vm2-sandbox-escape-via-nullish-this-receiver","title":"vm2 sandbox escape via nullish this receiver","severity":"critical","exploited":false,"published_at":"2026-09-18T14:19:12.003+00:00","url":"https://junglewise.ai/threats/cve-2026-93603-vm2-sandbox-escape-via-nullish-this-receiver"}],"high":7,"name":"Npm Vm2","rank":13,"slug":"vm2","score":148,"vendor":{"name":"Npm","slug":"npm"},"critical":20,"max_cvss":10,"max_epss":0.0103,"exploited":0,"vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/vm2"},{"hub":true,"top":[{"cve":"CVE-2026-84609","cvss":9.8,"epss":0.0067,"slug":"cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation","title":"Apple iOS APFS permissions bypass in path validation","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:36.133+00:00","url":"https://junglewise.ai/threats/cve-2026-84609-apple-ios-apfs-permissions-bypass-in-path-validation"},{"cve":"CVE-2026-84561","cvss":9.8,"epss":0.0068,"slug":"cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in","title":"Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS double free in memory management","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:32.173+00:00","url":"https://junglewise.ai/threats/cve-2026-84561-apple-ios-ipados-macos-tvos-visionos-and-watchos-double-free-in"},{"cve":"CVE-2026-65414","cvss":9.8,"epss":0.0108,"slug":"cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework","title":"Apple iOS and iPadOS out-of-bounds write in Accelerate Framework","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:25.057+00:00","url":"https://junglewise.ai/threats/cve-2026-65414-apple-ios-and-ipados-out-of-bounds-write-in-accelerate-framework"}],"high":22,"name":"Apple tvOS","rank":14,"slug":"tvos","score":142,"vendor":{"name":"Apple","slug":"apple"},"critical":4,"max_cvss":9.8,"max_epss":0.0108,"exploited":0,"vulnerabilities":78,"url":"https://junglewise.ai/threats/technologies/tvos"},{"hub":true,"top":[{"cve":"CVE-2026-83327","cvss":9.8,"epss":0.0046,"slug":"cve-2026-83327-oracle-e-business-suite-applications-framework-soap","title":"Oracle E-Business Suite Applications Framework SOAP authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:45.88+00:00","url":"https://junglewise.ai/threats/cve-2026-83327-oracle-e-business-suite-applications-framework-soap"},{"cve":"CVE-2026-87163","cvss":8.8,"epss":0.0043,"slug":"cve-2026-87163-oracle-e-business-suite-purchasing-privilege-escalation","title":"Oracle E-Business Suite Purchasing privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-15T20:19:03.947+00:00","url":"https://junglewise.ai/threats/cve-2026-87163-oracle-e-business-suite-purchasing-privilege-escalation"},{"cve":"CVE-2026-87155","cvss":8.8,"epss":0.0043,"slug":"cve-2026-87155-oracle-e-business-suite-product-hub-remote-code-execution","title":"Oracle E-Business Suite Product Hub remote code execution","severity":"high","exploited":false,"published_at":"2026-09-15T20:19:02.99+00:00","url":"https://junglewise.ai/threats/cve-2026-87155-oracle-e-business-suite-product-hub-remote-code-execution"}],"high":39,"name":"Oracle E-Business Suite","rank":15,"slug":"e-business-suite","score":125,"vendor":{"name":"Oracle","slug":"oracle"},"critical":1,"max_cvss":9.8,"max_epss":0.0046,"exploited":0,"vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/e-business-suite"},{"hub":true,"top":[{"cve":"CVE-2026-76460","cvss":10,"epss":0.1403,"slug":"cve-2026-76460-cisco-identity-services-engine-incorrect-privileged-api-use","title":"A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.","severity":"critical","exploited":true,"published_at":"2026-09-16T21:17:21.43+00:00","url":"https://junglewise.ai/threats/cve-2026-76460-cisco-identity-services-engine-incorrect-privileged-api-use"},{"cve":"CVE-2026-76423","cvss":10,"epss":0.0058,"slug":"cve-2026-76423-cisco-ise-rest-api-authentication-bypass","title":"Cisco ISE REST API authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-16T20:17:28.717+00:00","url":"https://junglewise.ai/threats/cve-2026-76423-cisco-ise-rest-api-authentication-bypass"},{"cve":"CVE-2026-20192","cvss":10,"epss":0.0046,"slug":"cve-2026-20192-cisco-identity-services-engine-improper-access-control","title":"Cisco Identity Services Engine improper access control","severity":"critical","exploited":false,"published_at":"2026-09-16T20:17:21.9+00:00","url":"https://junglewise.ai/threats/cve-2026-20192-cisco-identity-services-engine-improper-access-control"}],"high":5,"name":"Cisco Identity Services Engine","rank":16,"slug":"identity-services-engine","score":118,"vendor":{"name":"Cisco","slug":"cisco"},"critical":12,"max_cvss":10,"max_epss":0.1403,"exploited":1,"vulnerabilities":38,"url":"https://junglewise.ai/threats/technologies/identity-services-engine"},{"hub":true,"top":[{"cve":"CVE-2026-84625","cvss":9.1,"epss":0.0047,"slug":"cve-2026-84625-apple-ios-permissions-issue-allowing-user-fingerprinting","title":"Apple iOS permissions issue allowing user fingerprinting","severity":"critical","exploited":false,"published_at":"2026-09-14T21:17:37.523+00:00","url":"https://junglewise.ai/threats/cve-2026-84625-apple-ios-permissions-issue-allowing-user-fingerprinting"},{"cve":"CVE-2026-65391","cvss":8.8,"epss":0.0041,"slug":"cve-2026-65391-apple-safari-out-of-bounds-write-in-memory-handling","title":"Apple Safari out-of-bounds write in memory handling","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:22.877+00:00","url":"https://junglewise.ai/threats/cve-2026-65391-apple-safari-out-of-bounds-write-in-memory-handling"},{"cve":"CVE-2026-65390","cvss":8.8,"epss":0.0041,"slug":"cve-2026-65390-apple-webkit-integer-overflow-in-image-processing","title":"Apple WebKit integer overflow in image processing","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:22.767+00:00","url":"https://junglewise.ai/threats/cve-2026-65390-apple-webkit-integer-overflow-in-image-processing"}],"high":19,"name":"Apple Iphone Os","rank":17,"slug":"iphone-os","score":107,"vendor":{"name":"Apple","slug":"apple"},"critical":1,"max_cvss":9.1,"max_epss":0.0051,"exploited":0,"vulnerabilities":64,"url":"https://junglewise.ai/threats/technologies/iphone-os"},{"hub":true,"top":[{"cve":"CVE-2026-83039","cvss":9.9,"epss":0.0043,"slug":"cve-2026-83039-oracle-webcenter-portal-privilege-escalation-in-composer","title":"Oracle WebCenter Portal privilege escalation in Composer","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:12.297+00:00","url":"https://junglewise.ai/threats/cve-2026-83039-oracle-webcenter-portal-privilege-escalation-in-composer"},{"cve":"CVE-2026-73948","cvss":9.9,"epss":0.0043,"slug":"cve-2026-73948-oracle-webcenter-portal-privilege-escalation-in-composer","title":"Oracle WebCenter Portal privilege escalation in Composer","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:45.913+00:00","url":"https://junglewise.ai/threats/cve-2026-73948-oracle-webcenter-portal-privilege-escalation-in-composer"},{"cve":"CVE-2026-73963","cvss":9.8,"epss":0.0051,"slug":"cve-2026-73963-oracle-webcenter-portal-remote-code-execution-in-portlet-services","title":"Oracle WebCenter Portal remote code execution in Portlet Services","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:47.55+00:00","url":"https://junglewise.ai/threats/cve-2026-73963-oracle-webcenter-portal-remote-code-execution-in-portlet-services"}],"high":14,"name":"Oracle WebCenter Portal","rank":18,"slug":"webcenter-portal","score":102,"vendor":{"name":"Oracle","slug":"oracle"},"critical":10,"max_cvss":9.9,"max_epss":0.0051,"exploited":0,"vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/webcenter-portal"},{"hub":true,"top":[{"cve":"CVE-2026-83282","cvss":9.9,"epss":0.0042,"slug":"cve-2026-83282-oracle-business-intelligence-enterprise-edition-privilege","title":"Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:40.82+00:00","url":"https://junglewise.ai/threats/cve-2026-83282-oracle-business-intelligence-enterprise-edition-privilege"},{"cve":"CVE-2026-83283","cvss":9.8,"epss":0.0048,"slug":"cve-2026-83283-oracle-business-intelligence-enterprise-edition-unauthenticated","title":"Oracle Business Intelligence Enterprise Edition unauthenticated remote code execution","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:40.927+00:00","url":"https://junglewise.ai/threats/cve-2026-83283-oracle-business-intelligence-enterprise-edition-unauthenticated"},{"cve":"CVE-2026-83304","cvss":8.9,"epss":0.0033,"slug":"cve-2026-83304-oracle-business-intelligence-enterprise-edition-unauthorized-data","title":"Oracle Business Intelligence Enterprise Edition unauthorized data access in Analytics Web General","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:43.307+00:00","url":"https://junglewise.ai/threats/cve-2026-83304-oracle-business-intelligence-enterprise-edition-unauthorized-data"}],"high":27,"name":"Oracle Business Intelligence Enterprise Edition","rank":19,"slug":"business-intelligence-enterprise-edition","score":93,"vendor":{"name":"Oracle","slug":"oracle"},"critical":2,"max_cvss":9.9,"max_epss":0.0048,"exploited":0,"vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/business-intelligence-enterprise-edition"},{"hub":true,"top":[{"cve":"CVE-2026-83229","cvss":9.1,"epss":0.0046,"slug":"cve-2026-83229-oracle-siebel-crm-privilege-escalation-in-management-console","title":"Oracle Siebel CRM privilege escalation in Management Console","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:34.743+00:00","url":"https://junglewise.ai/threats/cve-2026-83229-oracle-siebel-crm-privilege-escalation-in-management-console"},{"cve":"CVE-2026-83202","cvss":9.1,"epss":0.0043,"slug":"cve-2026-83202-oracle-siebel-crm-deployment-authentication-bypass-in-server","title":"Oracle Siebel CRM Deployment authentication bypass in Server Infrastructure","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:31.763+00:00","url":"https://junglewise.ai/threats/cve-2026-83202-oracle-siebel-crm-deployment-authentication-bypass-in-server"},{"cve":"CVE-2026-83201","cvss":9.1,"epss":0.0043,"slug":"cve-2026-83201-oracle-siebel-crm-deployment-unauthenticated-data-access-in","title":"Oracle Siebel CRM Deployment unauthenticated data access in Server Infrastructure","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:31.64+00:00","url":"https://junglewise.ai/threats/cve-2026-83201-oracle-siebel-crm-deployment-unauthenticated-data-access-in"}],"high":21,"name":"Oracle Siebel CRM","rank":20,"slug":"siebel-crm","score":89,"vendor":{"name":"Oracle","slug":"oracle"},"critical":4,"max_cvss":9.1,"max_epss":0.0047,"exploited":0,"vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/siebel-crm"},{"hub":true,"top":[{"cve":"CVE-2026-73456","cvss":10,"epss":0.007,"slug":"cve-2026-73456-arista-eos-gnpsi-arbitrary-code-execution","title":"Arista EOS gNPSI arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-16T19:17:32.27+00:00","url":"https://junglewise.ai/threats/cve-2026-73456-arista-eos-gnpsi-arbitrary-code-execution"},{"cve":"CVE-2026-73453","cvss":10,"epss":0.007,"slug":"cve-2026-73453-arista-eos-p4runtime-arbitrary-code-execution","title":"Arista EOS P4Runtime arbitrary code execution","severity":"critical","exploited":false,"published_at":"2026-09-16T10:16:52.043+00:00","url":"https://junglewise.ai/threats/cve-2026-73453-arista-eos-p4runtime-arbitrary-code-execution"},{"cve":"CVE-2026-73437","cvss":9.6,"epss":0.0021,"slug":"cve-2026-73437-arista-eos-dhcp-relay-source-validation-bypass","title":"Arista EOS DHCP relay source validation bypass","severity":"critical","exploited":false,"published_at":"2026-09-15T22:16:58.22+00:00","url":"https://junglewise.ai/threats/cve-2026-73437-arista-eos-dhcp-relay-source-validation-bypass"}],"high":10,"name":"Arista EOS","rank":21,"slug":"eos","score":81,"vendor":{"name":"Arista","slug":"arista"},"critical":4,"max_cvss":10,"max_epss":0.0071,"exploited":0,"vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/eos"},{"hub":true,"top":[{"cve":"CVE-2026-83248","cvss":8.2,"epss":0.0043,"slug":"cve-2026-83248-oracle-commerce-guided-search-denial-of-service-and-information","title":"Oracle Commerce Guided Search denial of service and information disclosure","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:36.963+00:00","url":"https://junglewise.ai/threats/cve-2026-83248-oracle-commerce-guided-search-denial-of-service-and-information"},{"cve":"CVE-2026-83234","cvss":8.2,"epss":0.0034,"slug":"cve-2026-83234-oracle-commerce-guided-search-experience-manager-authentication","title":"Oracle Commerce Guided Search / Experience Manager authentication bypass","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:35.34+00:00","url":"https://junglewise.ai/threats/cve-2026-83234-oracle-commerce-guided-search-experience-manager-authentication"},{"cve":"CVE-2026-83258","cvss":8.1,"epss":0.0037,"slug":"cve-2026-83258-oracle-commerce-guided-search-and-experience-manager-remote","title":"Oracle Commerce Guided Search and Experience Manager remote compromise in Forge","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:38.073+00:00","url":"https://junglewise.ai/threats/cve-2026-83258-oracle-commerce-guided-search-and-experience-manager-remote"}],"high":24,"name":"Oracle Commerce Experience Manager","rank":22,"slug":"commerce-experience-manager","score":74,"vendor":{"name":"Oracle","slug":"oracle"},"critical":0,"max_cvss":8.2,"max_epss":0.0043,"exploited":0,"vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/commerce-experience-manager"},{"hub":true,"top":[{"cve":"CVE-2026-71133","cvss":10,"epss":0.0051,"slug":"cve-2026-71133-oracle-access-manager-authentication-bypass-in-http","title":"Oracle Access Manager authentication bypass in HTTP","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:42.343+00:00","url":"https://junglewise.ai/threats/cve-2026-71133-oracle-access-manager-authentication-bypass-in-http"},{"cve":"CVE-2026-73945","cvss":9.9,"epss":0.0043,"slug":"cve-2026-73945-oracle-access-manager-authentication-bypass-in-oracle-fusion","title":"Oracle Access Manager authentication bypass in Oracle Fusion Middleware","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:45.563+00:00","url":"https://junglewise.ai/threats/cve-2026-73945-oracle-access-manager-authentication-bypass-in-oracle-fusion"},{"cve":"CVE-2026-71163","cvss":9.9,"epss":0.0039,"slug":"cve-2026-71163-oracle-access-manager-authentication-bypass-in-http","title":"Oracle Access Manager authentication bypass in HTTP","severity":"critical","exploited":false,"published_at":"2026-09-15T20:17:42.49+00:00","url":"https://junglewise.ai/threats/cve-2026-71163-oracle-access-manager-authentication-bypass-in-http"}],"high":4,"name":"Oracle Access Manager","rank":23,"slug":"access-manager","score":73,"vendor":{"name":"Oracle","slug":"oracle"},"critical":10,"max_cvss":10,"max_epss":0.0051,"exploited":0,"vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/access-manager"},{"hub":true,"top":[{"cve":"CVE-2026-83248","cvss":8.2,"epss":0.0043,"slug":"cve-2026-83248-oracle-commerce-guided-search-denial-of-service-and-information","title":"Oracle Commerce Guided Search denial of service and information disclosure","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:36.963+00:00","url":"https://junglewise.ai/threats/cve-2026-83248-oracle-commerce-guided-search-denial-of-service-and-information"},{"cve":"CVE-2026-83236","cvss":8.2,"epss":0.003,"slug":"cve-2026-83236-oracle-commerce-guided-search-cross-site-request-forgery","title":"Oracle Commerce Guided Search cross-site request forgery","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:35.58+00:00","url":"https://junglewise.ai/threats/cve-2026-83236-oracle-commerce-guided-search-cross-site-request-forgery"},{"cve":"CVE-2026-83234","cvss":8.2,"epss":0.0034,"slug":"cve-2026-83234-oracle-commerce-guided-search-experience-manager-authentication","title":"Oracle Commerce Guided Search / Experience Manager authentication bypass","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:35.34+00:00","url":"https://junglewise.ai/threats/cve-2026-83234-oracle-commerce-guided-search-experience-manager-authentication"}],"high":23,"name":"Oracle Commerce Guided Search","rank":24,"slug":"commerce-guided-search","score":71,"vendor":{"name":"Oracle","slug":"oracle"},"critical":0,"max_cvss":8.2,"max_epss":0.0043,"exploited":0,"vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/commerce-guided-search"},{"hub":true,"top":[{"cve":"CVE-2026-83269","cvss":9.8,"epss":0.0048,"slug":"cve-2026-83269-oracle-bi-publisher-unauthenticated-remote-code-execution","title":"Oracle BI Publisher unauthenticated remote code execution","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:39.29+00:00","url":"https://junglewise.ai/threats/cve-2026-83269-oracle-bi-publisher-unauthenticated-remote-code-execution"},{"cve":"CVE-2026-83268","cvss":9.1,"epss":0.0046,"slug":"cve-2026-83268-oracle-bi-publisher-privilege-escalation-in-bi-platform-security","title":"Oracle BI Publisher privilege escalation in BI Platform Security","severity":"critical","exploited":false,"published_at":"2026-09-15T20:18:39.18+00:00","url":"https://junglewise.ai/threats/cve-2026-83268-oracle-bi-publisher-privilege-escalation-in-bi-platform-security"},{"cve":"CVE-2026-83315","cvss":8.8,"epss":0.0042,"slug":"cve-2026-83315-oracle-bi-publisher-privilege-escalation-in-soap-interface","title":"Oracle BI Publisher privilege escalation in SOAP interface","severity":"high","exploited":false,"published_at":"2026-09-15T20:18:44.52+00:00","url":"https://junglewise.ai/threats/cve-2026-83315-oracle-bi-publisher-privilege-escalation-in-soap-interface"}],"high":19,"name":"Oracle BI Publisher","rank":25,"slug":"bi-publisher","score":69,"vendor":{"name":"Oracle","slug":"oracle"},"critical":2,"max_cvss":9.8,"max_epss":0.0048,"exploited":0,"vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/bi-publisher"}],"previous":{"key":"2026-09-07","top":"Linux Kernel","period":{"end":"2026-09-13","start":"2026-09-07"},"totals":{"high":1701,"critical":319,"exploited":9,"technologies":1480,"vulnerabilities":3792},"url":"https://junglewise.ai/threats/weekly/2026-09-07"},"next":null}