Weekly Security Roundup: April 12 to April 19, 2026

Weekly security briefing from Sherlock Forensics covering April 12 to April 19, 2026. 31 vulnerabilities analyzed: 9 critical (CVSS 9.0+) and 22 high. Grouped by vendor with patching priorities.

The Week in Security

Cisco had 3 vulnerabilities this week including Cisco ISE RCE (CVSS 9.9). Other had 28 vulnerabilities this week including Critical (CVSS 9.8).

We tracked 31 vulnerabilities this week. 9 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Cisco: 3 Critical Flaws at Once

3 vulnerabilities across Cisco products this week. The worst: CVE-2026-20186 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Cisco.

Other Had a Rough Week

28 vulnerabilities across Other products this week. The worst: CVE-2026-4880 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Other.

By the Numbers

Total CVEs analyzed31
Critical (9.0+)9
High (7.0-8.9)22
Remote code execution12
Authentication bypass7
Cross-site scripting4
SQL injection1

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Cisco: Update immediately. 3 critical-severity issues patched this week.
  2. Other: Update immediately. 6 critical-severity issues patched this week.