2026 CVE Vulnerabilities
53,451 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32025 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that al... |
| CVE-2026-32024 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers ... |
| CVE-2026-32023 | HIGH | 7.1 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where ... |
| CVE-2026-32017 | HIGH | 7.1 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows a... |
| CVE-2026-32016 | HIGH | 7.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowl... |
| CVE-2026-32015 | HIGH | 7.8 | 0.1% | Mar 19, 2026 | OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows... |
| CVE-2026-32014 | HIGH | 8.6 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily... |
| CVE-2026-32013 | HIGH | 8.8 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.... |
| CVE-2026-32011 | HIGH | 8.7 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Go... |
| CVE-2026-32010 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort i... |
| CVE-2026-32009 | HIGH | 7.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that tru... |
| CVE-2026-32008 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigat... |
| CVE-2026-32007 | HIGH | 8.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that al... |
| CVE-2026-32005 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including blo... |
| CVE-2026-32004 | HIGH | 8.2 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classifica... |
| CVE-2026-32003 | HIGH | 7.2 | 0.5% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function ... |
| CVE-2026-29072 | HIGH | 7.5 | 0.2% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who ... |
| CVE-2026-27934 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack... |
| CVE-2026-3547 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds re... |
| CVE-2026-33346 | HIGH | 8.7 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33321 | HIGH | 7.6 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33302 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33301 | HIGH | 8.1 | 0.4% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-32622 | HIGH | 8.8 | 0.6% | Mar 19, 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S... |
| CVE-2026-26139 | HIGH | 8.6 | 0.6% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now