Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-12314

Memory safety bug fixed in Thunderbird 152_CVE-2026-12314

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.5 CVE-2026-12312

Memory safety bug fixed in Thunderbird 152_CVE-2026-12312

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.5 CVE-2026-12310

Memory safety bug fixed in Thunderbird 152_CVE-2026-12310

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.5 CVE-2026-12305

Memory safety bug fixed in Thunderbird 152_CVE-2026-12305

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.6 CVE-2026-53866

OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing_CVE-2026-53866

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute...

OpenClaw OpenClaw CVE
HIGH 7.2 CVE-2026-53865

OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH_CVE-2026-53865

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influ...

OpenClaw OpenClaw CVE
HIGH 7.6 CVE-2026-53864

OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables_CVE-2026-53864

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variabl...

OpenClaw OpenClaw CVE
HIGH 7 CVE-2026-53858

OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment Variable_CVE-2026-53858

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runt...

OpenClaw OpenClaw CVE
HIGH 8.6 CVE-2026-53857

OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy_CVE-2026-53857

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy...

OpenClaw OpenClaw CVE
HIGH 7.6 CVE-2026-53855

OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks_CVE-2026-53855

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell ...

OpenClaw OpenClaw CVE