2026 CVE Vulnerabilities
50,562 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35667 | MEDIUM | 6.9 | 0.1% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched k... |
| CVE-2026-35665 | MEDIUM | 6.9 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request... |
| CVE-2026-35664 | MEDIUM | 6.9 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired ... |
| CVE-2026-35662 | MEDIUM | 5.3 | 0.2% | Apr 10, 2026 | OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to mess... |
| CVE-2026-35661 | MEDIUM | 6.9 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query handling that allows... |
| CVE-2026-35659 | MEDIUM | 6.3 | 0.1% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could in... |
| CVE-2026-35658 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.2 contains a filesystem boundary bypass vulnerability in the image tool that fails to honor tools... |
| CVE-2026-35656 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when ... |
| CVE-2026-35655 | MEDIUM | 6.9 | 0.2% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicti... |
| CVE-2026-35654 | MEDIUM | 6.9 | 0.2% | Apr 10, 2026 | OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback invokes that allows... |
| CVE-2026-35651 | MEDIUM | 5.3 | 0.3% | Apr 10, 2026 | OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompt... |
| CVE-2026-35649 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny... |
| CVE-2026-35648 | MEDIUM | 5.9 | 0.2% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against c... |
| CVE-2026-35647 | MEDIUM | 6.9 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks an... |
| CVE-2026-35620 | MEDIUM | 5.4 | 0.4% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handle... |
| CVE-2026-35619 | MEDIUM | 5.3 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to e... |
| CVE-2026-35601 | MEDIUM | 4.1 | 0.2% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCale... |
| CVE-2026-35600 | MEDIUM | 5.4 | 0.2% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into M... |
| CVE-2026-35599 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function use... |
| CVE-2026-35598 | MEDIUM | 4.3 | 0.2% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesB... |
| CVE-2026-35596 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a... |
| CVE-2026-22560 | MEDIUM | 5.3 | 0.3% | Apr 10, 2026 | An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by... |
| CVE-2026-40227 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that... |
| CVE-2026-40226 | MEDIUM | 6.4 | 0.1% | Apr 10, 2026 | In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. |
| CVE-2026-40225 | MEDIUM | 6.4 | 0.1% | Apr 10, 2026 | In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel outp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now