Openclaw
588 CVEs tracked since 2026. Since Feb 2026, none of them reached CISA KEV.
Openclaw CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-02 | 35 | 0 |
| 2026-03 | 199 | 0 |
| 2026-04 | 174 | 0 |
| 2026-05 | 75 | 0 |
| 2026-06 | 61 | 0 |
| 2026-07 | 44 | 0 |
Products
The products that kept showing up in Openclaw's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Openclaw.
- CVE-2026-100604ClawHub Authentication Bypass via Former Publisher Skill Control5.4
- CVE-2026-100602ClawHub Changelog Preview Information Disclosure via Authorization Bypass6.5
- CVE-2026-100603ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports5.4
- CVE-2026-100601ClawHub SSRF via Unchecked DNS Resolution in Profile Image5.3
- CVE-2026-100600ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API5.3
- CVE-2026-100598OpenClaw before 2026.7.1 Approval Binding Logic Error7.1
- CVE-2026-100599OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome8.8
- CVE-2026-100597OpenClaw before 2026.7.1 Path Traversal via Filesystem Race7.8
- CVE-2026-100596OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration8.8
- CVE-2026-100595OpenClaw before 2026.7.1 Authorization Bypass via diagnostics6.5
- CVE-2026-100594OpenClaw before 2026.7.1 Authorization Bypass via trajectory export6.5
- CVE-2026-100593OpenClaw before 2026.7.1 Authentication Bypass via activation5.4
- CVE-2026-100592OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming6.3
- CVE-2026-100591OpenClaw before 2026.7.1 Authentication Bypass via Active Memory6.3
- CVE-2026-100589OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node8.3
The record
- Peak rank
- #2 in Mar 2026
- Busiest month shown
- Mar 2026, 199 CVEs
- Months with a KEV entry
- 0 since Feb 2026
- Monthly snapshots
- 6 since 2026