Weekly Security Roundup: April 19 to April 26, 2026

Make Sherlock Forensics your preferred source in Google Search

Weekly security briefing from Sherlock Forensics covering April 19 to April 26, 2026. 50 vulnerabilities analyzed: 8 critical (CVSS 9.0+) and 42 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 42 vulnerabilities this week including OpenClaw before 2026.3.31 contains Privilege (CVSS 9.9). WordPress had 1 high-severity issues worth watching. Oracle had 4 high-severity issues worth watching.

We tracked 50 vulnerabilities this week. 8 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

42 vulnerabilities across Other products this week. The worst: CVE-2026-41329 (CVSS 9.9) lets anyone bypass authentication. Patch now if you run Other.

WordPress Hit With CVSS 8.1

CVE-2026-5478 scores a 8.1. WordPress needs your attention.

Oracle Patches 4 Vulnerabilities

4 vulnerabilities across Oracle products this week. The worst: CVE-2026-34305 (CVSS 7.5) lets anyone bypass authentication. Patch now if you run Oracle.

IBM Patches 2 Vulnerabilities

2 vulnerabilities across IBM products this week. The worst: CVE-2026-3621 (CVSS 7.5) lets anyone bypass authentication. Patch now if you run IBM.

Google Hit With CVSS 7.2

CVE-2026-5464 scores a 7.2. Google lets attackers run code on your systems.

  • CVE-2026-5464: ExactMetrics - Google Analytics Remote (CVSS 7.2)

By the Numbers

Total CVEs analyzed50
Critical (9.0+)8
High (7.0-8.9)42
Remote code execution30
Authentication bypass19
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 8 critical-severity issues patched this week.
  2. WordPress: Review and patch 1 high-severity vulnerabilities when possible.
  3. Oracle: Review and patch 4 high-severity vulnerabilities when possible.
  4. IBM: Review and patch 2 high-severity vulnerabilities when possible.
  5. Google: Review and patch 1 high-severity vulnerabilities when possible.