2026 CVE Vulnerabilities

61,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54095Rejected reason: CVE ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-53826. Reason: This candidate i...
CVE-2026-53868HIGH8.7Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary...
CVE-2026-53867MEDIUM5.3Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo...
CVE-2026-53839MEDIUM6.5OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host...
CVE-2026-53838CRITICAL9.8OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes ...
CVE-2026-53837MEDIUM5.3OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to va...
CVE-2026-53836HIGH8.8OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows ...
CVE-2026-53835MEDIUM4.3OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that...
CVE-2026-53834MEDIUM6.5OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow...
CVE-2026-53833MEDIUM6.5OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows auth...
CVE-2026-53832HIGH7.1OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge...
CVE-2026-53831HIGH8.1OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that a...
CVE-2026-53830MEDIUM6.5OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and ...
CVE-2026-53829HIGH8.5OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide com...
CVE-2026-53828HIGH8.8OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authentic...
CVE-2026-53827MEDIUM6.5OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-con...
CVE-2026-53826MEDIUM4.3OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes th...
CVE-2026-53825HIGH7.1OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows aut...
CVE-2026-53824MEDIUM6.5OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to contin...
CVE-2026-53823HIGH8.6OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Sl...
CVE-2026-53822HIGH8.8OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between appro...
CVE-2026-53821HIGH8.8OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or...
CVE-2026-53820MEDIUM6.9OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path t...
CVE-2026-53609CRITICAL9.1ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.se...
CVE-2026-53608HIGH8.7ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostroph...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now