Weekly Security Roundup: April 17 to April 24, 2026

Make Sherlock Forensics your preferred source in Google Search

Weekly security briefing from Sherlock Forensics covering April 17 to April 24, 2026. 53 vulnerabilities analyzed: 7 critical (CVSS 9.0+) and 46 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 45 vulnerabilities this week including OpenClaw before 2026.3.31 contains Privilege (CVSS 9.9). WordPress had 1 high-severity issues worth watching. Oracle had 4 high-severity issues worth watching.

We tracked 53 vulnerabilities this week. 7 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

45 vulnerabilities across Other products this week. The worst: CVE-2026-41329 (CVSS 9.9) lets anyone bypass authentication. Patch now if you run Other.

WordPress Hit With CVSS 8.1

CVE-2026-5478 scores a 8.1. WordPress needs your attention.

Oracle Patches 4 Vulnerabilities

4 vulnerabilities across Oracle products this week. The worst: CVE-2026-34305 (CVSS 7.5) lets anyone bypass authentication. Patch now if you run Oracle.

IBM Patches 2 Vulnerabilities

2 vulnerabilities across IBM products this week. The worst: CVE-2026-3621 (CVSS 7.5) lets anyone bypass authentication. Patch now if you run IBM.

Google Hit With CVSS 7.2

CVE-2026-5464 scores a 7.2. Google lets attackers run code on your systems.

  • CVE-2026-5464: ExactMetrics - Google Analytics Remote (CVSS 7.2)

By the Numbers

Total CVEs analyzed53
Critical (9.0+)7
High (7.0-8.9)46
Remote code execution29
Authentication bypass22
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 7 critical-severity issues patched this week.
  2. WordPress: Review and patch 1 high-severity vulnerabilities when possible.
  3. Oracle: Review and patch 4 high-severity vulnerabilities when possible.
  4. IBM: Review and patch 2 high-severity vulnerabilities when possible.
  5. Google: Review and patch 1 high-severity vulnerabilities when possible.