Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-12301

Memory safety bug fixed in Thunderbird 152_CVE-2026-12301

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 5.3 CVE-2026-12300

Memory safety bug fixed in Thunderbird 152_CVE-2026-12300

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
MEDIUM 6 CVE-2026-53863

OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy_CVE-2026-53863

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ...

OpenClaw OpenClaw CVE
MEDIUM 5.3 CVE-2026-53861

OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS_CVE-2026-53861

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53859

OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency_CVE-2026-53859

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notati...

OpenClaw OpenClaw CVE
MEDIUM 5.7 CVE-2026-53856

OpenClaw < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json_CVE-2026-53856

OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad perm...

OpenClaw OpenClaw 2026.4.23 CVE
MEDIUM 6 CVE-2026-53854

OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands_CVE-2026-53854

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inher...

OpenClaw OpenClaw CVE
MEDIUM 6.3 CVE-2026-53851

OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass_CVE-2026-53851

OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled ...

OpenClaw OpenClaw CVE
MEDIUM 6.8 CVE-2026-53850

OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command_CVE-2026-53850

OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execu...

OpenClaw OpenClaw CVE
MEDIUM 5.3 CVE-2026-53847

OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope_CVE-2026-53847

OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator...

OpenClaw OpenClaw CVE