Weekly Security Roundup: April 20 to May 03, 2026

Weekly security briefing from Sherlock Forensics covering April 20 to May 03, 2026. 123 vulnerabilities analyzed: 14 critical (CVSS 9.0+) and 109 high. Grouped by vendor with patching priorities.

The Week in Security

Other had 100 vulnerabilities this week including OpenClaw before 2026.3.31 contains Privilege (CVSS 9.9). Weaver got hit with a CVSS 9.8 for Weaver (Fanwei) E-office versions Remote. Apache had 2 vulnerabilities this week including apache pony mail Vulnerability - Sherlock (CVSS 9.8).

We tracked 123 vulnerabilities this week. 14 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Other Had a Rough Week

100 vulnerabilities across Other products this week. The worst: CVE-2026-41329 (CVSS 9.9) lets anyone bypass authentication. Patch now if you run Other.

Weaver Hit With CVSS 9.8

CVE-2022-50993 scores a 9.8. Weaver lets attackers run code on your systems.

Apache Patches 2 Vulnerabilities

2 vulnerabilities across Apache products this week. The worst: CVE-2026-41873 (CVSS 9.8) lets anyone bypass authentication. Patch now if you run Apache.

IBM Patches 5 Vulnerabilities

5 vulnerabilities across IBM products this week. The worst: CVE-2026-6543 (CVSS 8.8) lets attackers run code on your systems. Patch now if you run IBM.

WordPress Had a Rough Week

10 vulnerabilities across WordPress products this week. The worst: CVE-2026-5478 (CVSS 8.1) needs your attention. Patch now if you run WordPress.

Oracle Patches 4 Vulnerabilities

4 vulnerabilities across Oracle products this week. The worst: CVE-2026-34305 (CVSS 7.5) lets anyone bypass authentication. Patch now if you run Oracle.

Google Hit With CVSS 7.2

CVE-2026-5464 scores a 7.2. Google lets attackers run code on your systems.

  • CVE-2026-5464: ExactMetrics – Google Analytics Remote (CVSS 7.2)

By the Numbers

Total CVEs analyzed123
Critical (9.0+)14
High (7.0-8.9)109
Remote code execution78
Authentication bypass43
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Other: Update immediately. 12 critical-severity issues patched this week.
  2. Weaver: Update immediately. 1 critical-severity issues patched this week.
  3. Apache: Update immediately. 1 critical-severity issues patched this week.
  4. IBM: Review and patch 5 high-severity vulnerabilities when possible.
  5. WordPress: Review and patch 10 high-severity vulnerabilities when possible.
  6. Oracle: Review and patch 4 high-severity vulnerabilities when possible.
  7. Google: Review and patch 1 high-severity vulnerabilities when possible.