Weekly Security Roundup: April 01 to April 08, 2026

Make Sherlock Forensics your preferred source in Google Search

Weekly security briefing from Sherlock Forensics covering April 01 to April 08, 2026. 16 vulnerabilities analyzed: 6 critical (CVSS 9.0+) and 10 high. Grouped by vendor with patching priorities.

The Week in Security

Windmill had 2 vulnerabilities this week including Windmill SQL Injection Scores 9.9 (CVSS 9.9). WordPress got hit with a CVSS 9.8 for Everest Forms WordPress. Weaver got hit with a CVSS 9.8 for Weaver E-cology Hit.

We tracked 16 vulnerabilities this week. 6 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Windmill Patches 2 Vulnerabilities

2 vulnerabilities across Windmill products this week. The worst: CVE-2026-23696 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Windmill.

WordPress Hit With CVSS 9.8

CVE-2026-3296 scores a 9.8. WordPress needs your attention.

Weaver Hit With CVSS 9.8

CVE-2026-22679 scores a 9.8. Weaver lets attackers run code on your systems.

Other Hit With CVSS 9.8

CVE-2021-4473 scores a 9.8. Other lets attackers run code on your systems.

Cockpit Hit With CVSS 9.8

CVE-2026-4631 scores a 9.8. Cockpit lets attackers run code on your systems.

IBM Patches 5 Vulnerabilities

5 vulnerabilities across IBM products this week. The worst: CVE-2026-1346 (CVSS 9.3) needs your attention. Patch now if you run IBM.

Red Hat Hit With CVSS 8.2

CVE-2026-4740 scores a 8.2. Red Hat lets anyone bypass authentication.

  • CVE-2026-4740: Red Hat ACM Certificate Forgery Scores (CVSS 8.2)

PowerJob Patches 2 Vulnerabilities

2 vulnerabilities across PowerJob products this week. The worst: CVE-2026-5739 (CVSS 7.3) lets attackers run code on your systems. Patch now if you run PowerJob.

Docker Hit With CVSS 7.3

CVE-2026-5741 scores a 7.3. Docker needs your attention.

OpenHarness Hit With CVSS 7.1

CVE-2026-22682 scores a 7.1. OpenHarness lets attackers run code on your systems.

By the Numbers

Total CVEs analyzed16
Critical (9.0+)6
High (7.0-8.9)10
Remote code execution8
Authentication bypass2
Cross-site scripting0
SQL injection1

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Windmill: Update immediately. 1 critical-severity issues patched this week.
  2. WordPress: Update immediately. 1 critical-severity issues patched this week.
  3. Weaver: Update immediately. 1 critical-severity issues patched this week.
  4. Other: Update immediately. 1 critical-severity issues patched this week.
  5. Cockpit: Update immediately. 1 critical-severity issues patched this week.
  6. IBM: Update immediately. 1 critical-severity issues patched this week.
  7. Red Hat: Review and patch 1 high-severity vulnerabilities when possible.
  8. PowerJob: Review and patch 2 high-severity vulnerabilities when possible.
  9. Docker: Review and patch 1 high-severity vulnerabilities when possible.
  10. OpenHarness: Review and patch 1 high-severity vulnerabilities when possible.