2026 CVE Vulnerabilities
67,342 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32013 | HIGH | 8.8 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.... |
| CVE-2026-32011 | HIGH | 8.7 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Go... |
| CVE-2026-32010 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort i... |
| CVE-2026-32009 | HIGH | 7.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that tru... |
| CVE-2026-32008 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigat... |
| CVE-2026-32007 | HIGH | 8.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that al... |
| CVE-2026-32006 | MEDIUM | 4.3 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are... |
| CVE-2026-32005 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including blo... |
| CVE-2026-32004 | HIGH | 8.2 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classifica... |
| CVE-2026-32003 | HIGH | 7.2 | 0.5% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function ... |
| CVE-2026-32002 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to en... |
| CVE-2026-32001 | MEDIUM | 5.4 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated wi... |
| CVE-2026-30873 | MEDIUM | 4.9 | 0.5% | Mar 19, 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, t... |
| CVE-2026-30872 | CRITICAL | 9.8 | 2.2% | Mar 19, 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md... |
| CVE-2026-30871 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md... |
| CVE-2026-29072 | HIGH | 7.5 | 0.2% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who ... |
| CVE-2026-28282 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a secu... |
| CVE-2026-27936 | MEDIUM | 5.3 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restrict... |
| CVE-2026-27935 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vuln... |
| CVE-2026-27934 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack... |
| CVE-2026-4428 | CRITICAL | 9.1 | 0.3% | Mar 19, 2026 | A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rej... |
| CVE-2026-4395 | CRITICAL | 9.8 | 0.3% | Mar 19, 2026 | Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote at... |
| CVE-2026-3849 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (E... |
| CVE-2026-3549 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buf... |
| CVE-2026-3547 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now