Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-12307

Memory safety bug fixed in Thunderbird 152_CVE-2026-12307

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
MEDIUM 5.3 CVE-2026-12306

Memory safety bug fixed in Thunderbird 152_CVE-2026-12306

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
MEDIUM 6.5 CVE-2026-12302

Mitigation bypass in the DOM: Security component_CVE-2026-12302

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird ...

Mozilla Firefox 115.37 CVE
MEDIUM 5.3 CVE-2026-12301

Memory safety bug fixed in Thunderbird 152_CVE-2026-12301

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 5.3 CVE-2026-12300

Memory safety bug fixed in Thunderbird 152_CVE-2026-12300

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 6 CVE-2026-53863

OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy_CVE-2026-53863

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ...

OpenClaw OpenClaw CVE
MEDIUM 5.3 CVE-2026-53861

OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS_CVE-2026-53861

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53859

OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency_CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notati...

OpenClaw OpenClaw CVE
MEDIUM 5.7 CVE-2026-53856

OpenClaw < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json_CVE-2026-53856

OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad perm...

OpenClaw OpenClaw 2026.4.23 CVE
MEDIUM 6 CVE-2026-53854

OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands_CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inher...

OpenClaw OpenClaw CVE