Weekly Security Roundup: April 26 to May 02, 2026

Weekly security briefing from Sherlock Forensics covering April 26 to May 02, 2026. 66 vulnerabilities analyzed: 6 critical (CVSS 9.0+) and 60 high. Grouped by vendor with patching priorities.

The Week in Security

Weaver got hit with a CVSS 9.8 for Weaver (Fanwei) E-office versions Remote. Other had 51 vulnerabilities this week including User Verification by PickPlugins (CVSS 9.8). Apache had 2 vulnerabilities this week including apache pony mail Vulnerability - Sherlock (CVSS 9.8).

We tracked 66 vulnerabilities this week. 6 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Weaver Hit With CVSS 9.8

CVE-2022-50993 scores a 9.8. Weaver lets attackers run code on your systems.

Other Had a Rough Week

51 vulnerabilities across Other products this week. The worst: CVE-2026-7458 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Other.

Apache Patches 2 Vulnerabilities

2 vulnerabilities across Apache products this week. The worst: CVE-2026-41873 (CVSS 9.8) lets anyone bypass authentication. Patch now if you run Apache.

IBM Patches 3 Vulnerabilities

3 vulnerabilities across IBM products this week. The worst: CVE-2026-6543 (CVSS 8.8) lets attackers run code on your systems. Patch now if you run IBM.

WordPress Patches 9 Vulnerabilities

9 vulnerabilities across WordPress products this week. The worst: CVE-2026-4062 (CVSS 7.5) lets attackers run code on your systems. Patch now if you run WordPress.

  • CVE-2026-4062: Geo MashuPlugin for SQL injection - Sherlock (CVSS 7.5)
  • CVE-2026-4061: Geo MashuPlugin for SQL injection - Sherlock (CVSS 7.5)
  • CVE-2026-4060: Geo MashuPlugin for SQL injection - Sherlock (CVSS 7.5)
  • CVE-2026-2892: Otter Blocks plugin for Vulnerability (CVSS 7.5)
  • CVE-2026-5113: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5112: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5111: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5110: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5109: Gravity Forms plugin for Cross-site (CVSS 7.2)

By the Numbers

Total CVEs analyzed66
Critical (9.0+)6
High (7.0-8.9)60
Remote code execution48
Authentication bypass15
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Weaver: Update immediately. 1 critical-severity issues patched this week.
  2. Other: Update immediately. 4 critical-severity issues patched this week.
  3. Apache: Update immediately. 1 critical-severity issues patched this week.
  4. IBM: Review and patch 3 high-severity vulnerabilities when possible.
  5. WordPress: Review and patch 9 high-severity vulnerabilities when possible.