2026 CVE Vulnerabilities

67,342 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32013HIGH8.8OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files....
CVE-2026-32011HIGH8.7OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Go...
CVE-2026-32010HIGH8.8OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort i...
CVE-2026-32009HIGH7.8OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that tru...
CVE-2026-32008HIGH7.1OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigat...
CVE-2026-32007HIGH8.1OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that al...
CVE-2026-32006MEDIUM4.3OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are...
CVE-2026-32005HIGH8.1OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including blo...
CVE-2026-32004HIGH8.2OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classifica...
CVE-2026-32003HIGH7.2OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function ...
CVE-2026-32002MEDIUM6.5OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to en...
CVE-2026-32001MEDIUM5.4OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated wi...
CVE-2026-30873MEDIUM4.9OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, t...
CVE-2026-30872CRITICAL9.8OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md...
CVE-2026-30871CRITICAL9.8OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md...
CVE-2026-29072HIGH7.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who ...
CVE-2026-28282MEDIUM6.5Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a secu...
CVE-2026-27936MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restrict...
CVE-2026-27935MEDIUM6.5Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vuln...
CVE-2026-27934HIGH7.5Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack...
CVE-2026-4428CRITICAL9.1A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rej...
CVE-2026-4395CRITICAL9.8Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote at...
CVE-2026-3849CRITICAL9.8Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (E...
CVE-2026-3549CRITICAL9.8Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buf...
CVE-2026-3547HIGH7.5Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now