VulnSea

Daily digest · in progress

Saturday 26 September 2026

A quiet day: only 100 new CVEs against a recent average of about 411 so far. Of those, 1 critical and 32 high. openclaw was the most-affected vendor with 74.

100
New CVEs
1
Critical
0
KEV additions
44
Records changed

New this day, ranked by depth score

The 12 that matter most of the 100 published.

CVE-2026-18143Critical· 9.8
today

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME…

▾ MidnightAddify · Request a Quote for WooCommercevia NVD
CVE-2026-100599High· 8.8
today

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands

OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command arrays and executes them on a paired node witho…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100596High· 8.8
today

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands

OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary stdio MCP commands that execute with OpenClaw proc…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100587High· 8.8
today

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command

OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation command. Non-owner channel senders can install arbitrary plugins and execute MCP processes with OpenClaw user privileg…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100586High· 8.8
today

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings

OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-owner channel senders with command access can create bindings to the native Codex runtime and execute host-capab…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100580High· 8.8
today

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job

OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An act…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100575High· 8.8
today

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages

OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowed participants can trigger Slack agents and access tools and data granted to those agents by bypassing configure…

▾ Twilightopenclaw · slackvia NVD
CVE-2026-100552High· 8.8
today

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools

OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runtime tools. A conversation-level tools.allow rule filtered OpenClaw tools but did not restrict the shell, process…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100544High· 8.8
today

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status

openclaw's @openclaw/voice-call package before 2026.8.1 launches the configured agent for classic inbound voice calls without propagating the caller's identity or non-owner status. As a result, owner-only tool filtering can fail open and…

▾ Twilightopenclaw · voice-callvia NVD
CVE-2026-100520High· 8.8
today

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory tra…

▾ Twilightcrivion · Laranodevia NVD
CVE-2026-100589High· 8.3
today

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over s…

▾ TwilightOpenClaw · OpenClawvia NVD
CVE-2026-100588High· 8.3
today

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator sc…

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator sc…

▾ TwilightOpenClaw · OpenClawvia NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45
  • CVE-2026-88414MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do).66
  • CVE-2026-88418CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms60
  • CVE-2026-85542IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality66
  • CVE-2026-40575OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing50
  • CVE-2026-73253Mongoose is an embedded web server and network library50

Most-affected vendors

By CVEs published in the period.