2026 CVE Vulnerabilities

50,562 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35667MEDIUM6.9OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched k...
CVE-2026-35665MEDIUM6.9OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request...
CVE-2026-35664MEDIUM6.9OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired ...
CVE-2026-35662MEDIUM5.3OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to mess...
CVE-2026-35661MEDIUM6.9OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query handling that allows...
CVE-2026-35659MEDIUM6.3OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could in...
CVE-2026-35658MEDIUM6.5OpenClaw before 2026.3.2 contains a filesystem boundary bypass vulnerability in the image tool that fails to honor tools...
CVE-2026-35656MEDIUM6.5OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when ...
CVE-2026-35655MEDIUM6.9OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicti...
CVE-2026-35654MEDIUM6.9OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback invokes that allows...
CVE-2026-35651MEDIUM5.3OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompt...
CVE-2026-35649MEDIUM6.5OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny...
CVE-2026-35648MEDIUM5.9OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against c...
CVE-2026-35647MEDIUM6.9OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks an...
CVE-2026-35620MEDIUM5.4OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handle...
CVE-2026-35619MEDIUM5.3OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to e...
CVE-2026-35601MEDIUM4.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCale...
CVE-2026-35600MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into M...
CVE-2026-35599MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function use...
CVE-2026-35598MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesB...
CVE-2026-35596MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a...
CVE-2026-22560MEDIUM5.3An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by...
CVE-2026-40227MEDIUM5.5In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that...
CVE-2026-40226MEDIUM6.4In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
CVE-2026-40225MEDIUM6.4In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel outp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now