Weekly Security Roundup: April 17 to April 24, 2026

Weekly security briefing from Sherlock Forensics covering April 17 to April 24, 2026. 53 vulnerabilities analyzed: 7 critical (CVSS 9.0+) and 46 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 45 vulnerabilities this week including OpenClaw before 2026.3.31 contains Privilege (CVSS 9.9). WordPress had 1 high-severity issues worth watching. Oracle had 4 high-severity issues worth watching.

We tracked 53 vulnerabilities this week. 7 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

45 vulnerabilities across Other products this week. The worst: CVE-2026-41329 (CVSS 9.9) lets anyone bypass authentication. Patch now if you run Other.

WordPress Hit With CVSS 8.1

CVE-2026-5478 scores a 8.1. WordPress needs your attention.

Oracle Patches 4 Vulnerabilities

4 vulnerabilities across Oracle products this week. The worst: CVE-2026-34305 (CVSS 7.5) lets anyone bypass authentication. Patch now if you run Oracle.

IBM Patches 2 Vulnerabilities

2 vulnerabilities across IBM products this week. The worst: CVE-2026-3621 (CVSS 7.5) lets anyone bypass authentication. Patch now if you run IBM.

Google Hit With CVSS 7.2

CVE-2026-5464 scores a 7.2. Google lets attackers run code on your systems.

  • CVE-2026-5464: ExactMetrics – Google Analytics Remote (CVSS 7.2)

By the Numbers

Total CVEs analyzed53
Critical (9.0+)7
High (7.0-8.9)46
Remote code execution29
Authentication bypass22
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 7 critical-severity issues patched this week.
  2. WordPress: Review and patch 1 high-severity vulnerabilities when possible.
  3. Oracle: Review and patch 4 high-severity vulnerabilities when possible.
  4. IBM: Review and patch 2 high-severity vulnerabilities when possible.
  5. Google: Review and patch 1 high-severity vulnerabilities when possible.