Back Sherlockforensics Weekly Security Roundup: June 29 to July 12, 2026
Weekly security briefing from Sherlock Forensics covering June 29 to July 12, 2026. 180 vulnerabilities analyzed: 24 critical (CVSS 9.0+) and 156 high. Grouped by vendor with patching priorities.
Adobe had 2 vulnerabilities this week including Adobe Campaign Classic (ACC) Remote code execution (CVSS 10.0). Other had 150 vulnerabilities this week including Server-side request forgery (ssrf) Privilege escalation (CVSS 9.9). IBM had 17 vulnerabilities this week including IBM Langflow OSS 1.0.0 Vulnerability (CVSS 9.6).
We tracked 180 vulnerabilities this week. 24 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.
2 vulnerabilities across Adobe products this week. The worst: CVE-2026-48286 (CVSS 10.0) lets attackers run code on your systems. Patch now if you run Adobe.
150 vulnerabilities across Other products this week. The worst: CVE-2026-57100 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Other.
17 vulnerabilities across IBM products this week. The worst: CVE-2026-10140 (CVSS 9.6) lets anyone bypass authentication. Patch now if you run IBM.
6 vulnerabilities across WordPress products this week. The worst: CVE-2026-6070 (CVSS 9.1) lets attackers run code on your systems. Patch now if you run WordPress.
2 vulnerabilities across PHP products this week. The worst: CVE-2026-57995 (CVSS 8.8) lets anyone bypass authentication. Patch now if you run PHP.
2 vulnerabilities across Microsoft products this week. The worst: CVE-2026-54998 (CVSS 8.8) lets anyone bypass authentication. Patch now if you run Microsoft.
CVE-2026-58467 scores a 7.5. Cockpit lets attackers run code on your systems.
One action item per vendor. Start at the top and work down.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
