CVE-2026-6977: A security vulnerability has Authorization
A security vulnerability has authorization bypass (CVE-2026-6977) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
Weekly Roundup
Weekly cybersecurity vulnerability roundup from Sherlock Forensics. 50 critical and high-severity CVEs analyzed from April 19 to April 26, 2026 with impact assessment and remediation guidance.
50 Vulnerabilities This Week
A security vulnerability has authorization bypass (CVE-2026-6977) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
KLiK SocialMediaWebsite up to SQL injection (CVE-2026-7002) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
PicoClaw up to 0.2.4. command injection (CVE-2026-6987) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
Exposure of sensitive information privilege escalation (CVE-2026-21515) scores CVSS 9.9 CRITICAL. Analysis of affected systems and remediation steps.
BridgeHead FileStore versions prior remote code execution (CVE-2026-39920) scores CVSS 9.8 CRITICAL. Analysis of affected systems and remediation steps.
ExactMetrics – Google Analytics remote code execution (CVE-2026-5464) scores CVSS 7.2 HIGH. Analysis of affected systems and remediation steps.
Drag and Drop File remote code execution (CVE-2026-5364) scores CVSS 8.1 HIGH. Analysis of affected systems and remediation steps.
KTransformers through 0.5.3 unsafe deserialization (CVE-2026-26210) scores CVSS 9.8 CRITICAL. Analysis of affected systems and remediation steps.
OpenClaw before 2026.3.22 access authorization bypass (CVE-2026-41353) scores CVSS 8.1 HIGH. Analysis of affected systems and remediation steps.
Borg SPM 2007 (Sales remote code execution (CVE-2026-6885) scores CVSS 9.8 CRITICAL. Analysis of affected systems and remediation steps.
OpenClaw before 2026.3.28 agentic vulnerability (CVE-2026-41349) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
Kofax Capture, now referred remote code execution (CVE-2026-23751) scores CVSS 9.8 CRITICAL. Analysis of affected systems and remediation steps.
OpenClaw before 2026.3.31 remote remote code execution (CVE-2026-41352) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
A flaw was found vulnerability (CVE-2026-6859) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
IBM Total Storage Service remote code execution (CVE-2026-5935) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
Beghelli Sicuro24 SicuroWeb embeds vulnerability (CVE-2026-41468) scores CVSS 8.7 HIGH. Analysis of affected systems and remediation steps.
IBM WebSphere Application Server vulnerability (CVE-2026-3621) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.
WeKan before 8.35 server-side request vulnerability (CVE-2026-41455) scores CVSS 8.5 HIGH. Analysis of affected systems and remediation steps.
WeKan before 8.35 missing authorization vulnerability (CVE-2026-41454) scores CVSS 8.3 HIGH. Analysis of affected systems and remediation steps.
Hermes WebUI directory traversal (CVE-2026-6832) scores CVSS 8.1 HIGH. Analysis of affected systems and remediation steps.
FreePBX API module remote code execution (CVE-2026-40520) scores CVSS 7.2 HIGH. Analysis of affected systems and remediation steps.
Oracle denial of service vulnerability (CVE-2026-34282) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.
HTTP Headers plugin remote code execution (CVE-2026-4132) scores CVSS 7.2 HIGH. Analysis of affected systems and remediation steps.
Incorrect authorization vulnerability (CVE-2026-33519) scores CVSS 9.8 CRITICAL. Analysis of affected systems and remediation steps.
Oracle vulnerability (CVE-2026-34305) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.
Oracle vulnerability (CVE-2026-34292) scores CVSS 7.2 HIGH. Analysis of affected systems and remediation steps.
Oracle vulnerability (CVE-2026-22016) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.
The Everest Forms plugin file read (CVE-2026-5478) scores CVSS 8.1 HIGH. Analysis of affected systems and remediation steps.
A vulnerability was determined buffer overflow (CVE-2026-6631) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
OpenClaw before 2026.3.31 contains file read (CVE-2026-41296) scores CVSS 8.2 HIGH. Analysis of affected systems and remediation steps.
Vvveb prior to 1.0.8.1 contains file read (CVE-2026-34428) scores CVSS 7.7 HIGH. Analysis of affected systems and remediation steps.
Vvveb CMS 1.0.8 contains remote code execution (CVE-2026-6249) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
Vvveb prior to 1.0.8.1 contains remote code execution (CVE-2026-39918) scores CVSS 9.8 CRITICAL. Analysis of affected systems and remediation steps.
A vulnerability was found vulnerability (CVE-2026-6662) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
A security vulnerability has vulnerability (CVE-2026-6635) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
OpenClaw before 2026.3.31 contains vulnerability (CVE-2026-41297) scores CVSS 7.6 HIGH. Analysis of affected systems and remediation steps.
OpenClaw before 2026.3.31 contains privilege escalation (CVE-2026-41329) scores CVSS 9.9 CRITICAL. Analysis of affected systems and remediation steps.
OpenClaw before 2026.3.28 contains access control (CVE-2026-41299) scores CVSS 7.1 HIGH. Analysis of affected systems and remediation steps.
The wpForo Forum plugin remote code execution (CVE-2026-6248) scores CVSS 8.1 HIGH. Analysis of affected systems and remediation steps.
A vulnerability was determined directory traversal (CVE-2026-6568) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
A vulnerability was found vulnerability (CVE-2026-6602) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
CVE-2026-6596 scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
ThreatSonar Anti-Ransomware developed by directory traversal (CVE-2026-5966) scores CVSS 8.1 HIGH. Analysis of affected systems and remediation steps.
A vulnerability was detected buffer overflow (CVE-2026-6581) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.
CVE-2026-6605 scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
A vulnerability was identified vulnerability (CVE-2026-6604) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
A vulnerability was determined code injection (CVE-2026-6603) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
A vulnerability was identified vulnerability (CVE-2026-6569) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
A security vulnerability has vulnerability (CVE-2026-6580) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.
A vulnerability has been vulnerability (CVE-2026-6574) scores CVSS 7.3 HIGH. Analysis of affected systems and remediation steps.