2026 CVE Vulnerabilities
70,015 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28465 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi... |
| CVE-2026-28464 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke... |
| CVE-2026-28463 | MEDIUM | 5.5 | 0.2% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist valida... |
| CVE-2026-28462 | CRITICAL | 9.1 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplie... |
| CVE-2026-28459 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli... |
| CVE-2026-28458 | MEDIUM | 5.4 | 0.3% | Mar 5, 2026 | OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed ... |
| CVE-2026-28457 | HIGH | 7.9 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled)... |
| CVE-2026-28456 | HIGH | 8.6 | 0.4% | Mar 5, 2026 | OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently c... |
| CVE-2026-28454 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowin... |
| CVE-2026-28453 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal... |
| CVE-2026-28452 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src... |
| CVE-2026-28451 | CRITICAL | 9.3 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that al... |
| CVE-2026-28450 | HIGH | 8.2 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap... |
| CVE-2026-28448 | CRITICAL | 9.4 | 0.4% | Mar 5, 2026 | OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enable... |
| CVE-2026-28447 | MEDIUM | 6.5 | 0.4% | Mar 5, 2026 | OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that ... |
| CVE-2026-28446 | CRITICAL | 9.8 | 0.7% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass... |
| CVE-2026-28395 | CRITICAL | 9.1 | 0.4% | Mar 5, 2026 | OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extensi... |
| CVE-2026-28394 | MEDIUM | 6.9 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attacke... |
| CVE-2026-28393 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading... |
| CVE-2026-28392 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler tha... |
| CVE-2026-28391 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec req... |
| CVE-2026-21622 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows... |
| CVE-2026-29188 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2026-29081 | HIGH | 8.8 | 0.3% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to... |
| CVE-2026-29077 | HIGH | 7.1 | 0.2% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now