Weekly Security Roundup: May 11 to May 24, 2026

Weekly security briefing from Sherlock Forensics covering May 11 to May 24, 2026. 233 vulnerabilities analyzed: 30 critical (CVSS 9.0+) and 203 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 188 vulnerabilities this week including Improper control of generation Code (CVSS 9.9). WordPress had 15 vulnerabilities this week including InfusedWoo Pro plugin for PrivilegEscalation (CVSS 9.8). PHP got hit with a CVSS 9.8 for phpMyFAQ before 4.1.2 unauthenticated SQL.

We tracked 233 vulnerabilities this week. 30 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

188 vulnerabilities across Other products this week. The worst: CVE-2026-42898 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Other.

WordPress Had a Rough Week

15 vulnerabilities across WordPress products this week. The worst: CVE-2026-6510 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run WordPress.

  • CVE-2026-6510: InfusedWoo Pro plugin for PrivilegEscalation (CVSS 9.8)
  • CVE-2026-6271: Career Section plugin foRemote codExecution (CVSS 9.8)
  • CVE-2026-5229: Form Notify plugin for Authentication bypass (CVSS 9.8)
  • CVE-2026-6512: InfusedWoo Pro plugin for Authorization (CVSS 9.1)
  • CVE-2026-6506: InfusedWoo Pro plugin for PrivilegEscalation (CVSS 8.8)
  • CVE-2026-3425: RTMKit Addons for Elementor Authorization (CVSS 8.8)
  • CVE-2026-5396: Fluent Forms plugin for Authorization bypass (CVSS 8.2)
  • CVE-2026-4030: Database Backup for WordPress File read (CVSS 8.1)
  • CVE-2026-6514: InfusedWoo Pro plugin for File read (CVSS 7.5)
  • CVE-2026-6403: Quick Playground plugin for Directory (CVSS 7.5)
  • CVE-2026-4798: Avada Builder plugin for SQL injection (CVSS 7.5)
  • CVE-2026-4031: Database Backup for WordPress Authorization (CVSS 7.5)
  • CVE-2026-4029: Database Backup for WordPress Vulnerability (CVSS 7.5)
  • CVE-2026-6690: LifePress plugin for WordPress Cross-site (CVSS 7.2)
  • CVE-2026-3718: ManageWP Worker plugin for Cross-site (CVSS 7.2)

PHP Hit With CVSS 9.8

CVE-2026-46364 scores a 9.8. PHP lets attackers run code on your systems.

  • CVE-2026-46364: phpMyFAQ before 4.1.2 unauthenticated SQL (CVSS 9.8)

Spring Framework Hit With CVSS 9.6

CVE-2026-34263 scores a 9.6. Spring Framework lets attackers run code on your systems.

SAP Hit With CVSS 9.6

CVE-2026-34260 scores a 9.6. SAP lets attackers run code on your systems.

Adobe Had a Rough Week

16 vulnerabilities across Adobe products this week. The worst: CVE-2026-34659 (CVSS 9.6) lets attackers run code on your systems. Patch now if you run Adobe.

Siemens Patches 4 Vulnerabilities

4 vulnerabilities across Siemens products this week. The worst: CVE-2026-22924 (CVSS 9.1) lets attackers run code on your systems. Patch now if you run Siemens.

Microsoft Azure Hit With CVSS 9.1

CVE-2026-33117 scores a 9.1. Microsoft Azure lets attackers run code on your systems.

Microsoft Patches 5 Vulnerabilities

5 vulnerabilities across Microsoft products this week. The worst: CVE-2026-35438 (CVSS 8.3) lets anyone bypass authentication. Patch now if you run Microsoft.

Google Hit With CVSS 7.1

CVE-2026-5371 scores a 7.1. Google lets attackers run code on your systems.

By the Numbers

Total CVEs analyzed233
Critical (9.0+)30
High (7.0-8.9)203
Remote code execution111
Authentication bypass117
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 18 critical-severity issues patched this week.
  2. WordPress: Update immediately. 4 critical-severity issues patched this week.
  3. PHP: Update immediately. 1 critical-severity issues patched this week.
  4. Spring Framework: Update immediately. 1 critical-severity issues patched this week.
  5. SAP: Update immediately. 1 critical-severity issues patched this week.
  6. Adobe: Update immediately. 2 critical-severity issues patched this week.
  7. Siemens: Update immediately. 2 critical-severity issues patched this week.
  8. Microsoft Azure: Update immediately. 1 critical-severity issues patched this week.
  9. Microsoft: Review and patch 5 high-severity vulnerabilities when possible.
  10. Google: Review and patch 1 high-severity vulnerabilities when possible.