Weekly Security Roundup: April 01 to April 08, 2026

Weekly security briefing from Sherlock Forensics covering April 01 to April 08, 2026. 16 vulnerabilities analyzed: 6 critical (CVSS 9.0+) and 10 high. Grouped by vendor with patching priorities.

The Week in Security

Windmill had 2 vulnerabilities this week including Windmill SQL Injection Scores 9.9 (CVSS 9.9). WordPress got hit with a CVSS 9.8 for Everest Forms WordPress. Weaver got hit with a CVSS 9.8 for Weaver E-cology Hit.

We tracked 16 vulnerabilities this week. 6 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Windmill Patches 2 Vulnerabilities

2 vulnerabilities across Windmill products this week. The worst: CVE-2026-23696 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Windmill.

WordPress Hit With CVSS 9.8

CVE-2026-3296 scores a 9.8. WordPress needs your attention.

Weaver Hit With CVSS 9.8

CVE-2026-22679 scores a 9.8. Weaver lets attackers run code on your systems.

Other Hit With CVSS 9.8

CVE-2021-4473 scores a 9.8. Other lets attackers run code on your systems.

Cockpit Hit With CVSS 9.8

CVE-2026-4631 scores a 9.8. Cockpit lets attackers run code on your systems.

IBM Patches 5 Vulnerabilities

5 vulnerabilities across IBM products this week. The worst: CVE-2026-1346 (CVSS 9.3) needs your attention. Patch now if you run IBM.

Red Hat Hit With CVSS 8.2

CVE-2026-4740 scores a 8.2. Red Hat lets anyone bypass authentication.

  • CVE-2026-4740: Red Hat ACM Certificate Forgery Scores (CVSS 8.2)

PowerJob Patches 2 Vulnerabilities

2 vulnerabilities across PowerJob products this week. The worst: CVE-2026-5739 (CVSS 7.3) lets attackers run code on your systems. Patch now if you run PowerJob.

Docker Hit With CVSS 7.3

CVE-2026-5741 scores a 7.3. Docker needs your attention.

OpenHarness Hit With CVSS 7.1

CVE-2026-22682 scores a 7.1. OpenHarness lets attackers run code on your systems.

By the Numbers

Total CVEs analyzed16
Critical (9.0+)6
High (7.0-8.9)10
Remote code execution8
Authentication bypass2
Cross-site scripting0
SQL injection1

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Windmill: Update immediately. 1 critical-severity issues patched this week.
  2. WordPress: Update immediately. 1 critical-severity issues patched this week.
  3. Weaver: Update immediately. 1 critical-severity issues patched this week.
  4. Other: Update immediately. 1 critical-severity issues patched this week.
  5. Cockpit: Update immediately. 1 critical-severity issues patched this week.
  6. IBM: Update immediately. 1 critical-severity issues patched this week.
  7. Red Hat: Review and patch 1 high-severity vulnerabilities when possible.
  8. PowerJob: Review and patch 2 high-severity vulnerabilities when possible.
  9. Docker: Review and patch 1 high-severity vulnerabilities when possible.
  10. OpenHarness: Review and patch 1 high-severity vulnerabilities when possible.