Weekly Security Roundup: April 26 to May 02, 2026

Make Sherlock Forensics your preferred source in Google Search

Weekly security briefing from Sherlock Forensics covering April 26 to May 02, 2026. 66 vulnerabilities analyzed: 6 critical (CVSS 9.0+) and 60 high. Grouped by vendor with patching priorities.

The Week in Security

Weaver got hit with a CVSS 9.8 for Weaver (Fanwei) E-office versions Remote. Other had 51 vulnerabilities this week including User Verification by PickPlugins (CVSS 9.8). Apache had 2 vulnerabilities this week including apache pony mail Vulnerability - Sherlock (CVSS 9.8).

We tracked 66 vulnerabilities this week. 6 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.

Weaver Hit With CVSS 9.8

CVE-2022-50993 scores a 9.8. Weaver lets attackers run code on your systems.

Other Had a Rough Week

51 vulnerabilities across Other products this week. The worst: CVE-2026-7458 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Other.

Apache Patches 2 Vulnerabilities

2 vulnerabilities across Apache products this week. The worst: CVE-2026-41873 (CVSS 9.8) lets anyone bypass authentication. Patch now if you run Apache.

IBM Patches 3 Vulnerabilities

3 vulnerabilities across IBM products this week. The worst: CVE-2026-6543 (CVSS 8.8) lets attackers run code on your systems. Patch now if you run IBM.

WordPress Patches 9 Vulnerabilities

9 vulnerabilities across WordPress products this week. The worst: CVE-2026-4062 (CVSS 7.5) lets attackers run code on your systems. Patch now if you run WordPress.

  • CVE-2026-4062: Geo MashuPlugin for SQL injection - Sherlock (CVSS 7.5)
  • CVE-2026-4061: Geo MashuPlugin for SQL injection - Sherlock (CVSS 7.5)
  • CVE-2026-4060: Geo MashuPlugin for SQL injection - Sherlock (CVSS 7.5)
  • CVE-2026-2892: Otter Blocks plugin for Vulnerability (CVSS 7.5)
  • CVE-2026-5113: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5112: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5111: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5110: Gravity Forms plugin for Cross-site (CVSS 7.2)
  • CVE-2026-5109: Gravity Forms plugin for Cross-site (CVSS 7.2)

By the Numbers

Total CVEs analyzed66
Critical (9.0+)6
High (7.0-8.9)60
Remote code execution48
Authentication bypass15
Cross-site scripting0
SQL injection0

What To Do This Week

One action item per vendor. Start at the top and work down.

  1. Weaver: Update immediately. 1 critical-severity issues patched this week.
  2. Other: Update immediately. 4 critical-severity issues patched this week.
  3. Apache: Update immediately. 1 critical-severity issues patched this week.
  4. IBM: Review and patch 3 high-severity vulnerabilities when possible.
  5. WordPress: Review and patch 9 high-severity vulnerabilities when possible.