Weekly Security Roundup: April 27 to May 10, 2026

Weekly security briefing from Sherlock Forensics covering April 27 to May 10, 2026. 243 vulnerabilities analyzed: 45 critical (CVSS 9.0+) and 198 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 210 vulnerabilities this week including Exposure of sensitive information (CVSS 10.0). WordPress had 22 vulnerabilities this week including MoreConvert Pro plugin for Authentication (CVSS 9.8). Weaver got hit with a CVSS 9.8 for Weaver (Fanwei) E-office versions Remote.

We tracked 243 vulnerabilities this week. 45 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

210 vulnerabilities across Other products this week. The worst: CVE-2026-42826 (CVSS 10.0) lets anyone bypass authentication. Patch now if you run Other.

WordPress Had a Rough Week

22 vulnerabilities across WordPress products this week. The worst: CVE-2026-5722 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run WordPress.

Weaver Hit With CVSS 9.8

CVE-2022-50993 scores a 9.8. Weaver lets attackers run code on your systems.

Apache Patches 4 Vulnerabilities

4 vulnerabilities across Apache products this week. The worst: CVE-2026-41873 (CVSS 9.8) lets anyone bypass authentication. Patch now if you run Apache.

Microsoft Hit With CVSS 9.6

CVE-2026-33823 scores a 9.6. Microsoft lets anyone bypass authentication.

IBM Patches 3 Vulnerabilities

3 vulnerabilities across IBM products this week. The worst: CVE-2026-6543 (CVSS 8.8) lets attackers run code on your systems. Patch now if you run IBM.

Oracle Hit With CVSS 8.7

CVE-2026-35228 scores a 8.7. Oracle lets attackers run code on your systems.

Ivanti Hit With CVSS 7.4

CVE-2026-7821 scores a 7.4. Ivanti lets anyone bypass authentication.

  • CVE-2026-7821: ivanti endpoint manager mobile Information (CVSS 7.4)

By the Numbers

Total CVEs analyzed243
Critical (9.0+)45
High (7.0-8.9)198
Remote code execution152
Authentication bypass87
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 35 critical-severity issues patched this week.
  2. WordPress: Update immediately. 6 critical-severity issues patched this week.
  3. Weaver: Update immediately. 1 critical-severity issues patched this week.
  4. Apache: Update immediately. 2 critical-severity issues patched this week.
  5. Microsoft: Update immediately. 1 critical-severity issues patched this week.
  6. IBM: Review and patch 3 high-severity vulnerabilities when possible.
  7. Oracle: Review and patch 1 high-severity vulnerabilities when possible.
  8. Ivanti: Review and patch 1 high-severity vulnerabilities when possible.