2 vulnerabilities across 1 product scored HIGH or above on September 26, 2026.
- π HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-12227 (visualcomposer/visual_composer_website_builder) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-09-24 bulletin.
- [UPGRADED] CVE-2026-28325 (solarwinds/observability_self-hosted) β F1: exploitable β functional, AAS: 9.6 β 11.6 (HIGH β HIGH). Originally in 2026-09-22 bulletin.
- [UPGRADED] CVE-2026-77521 (1panel-dev/maxkb) β F1: exploitable β functional, AAS: 11.2 β 13.2 (HIGH β CRITICAL). Originally in 2026-09-21 bulletin.
- [UPGRADED] CVE-2026-92229 (wpmudev/forminator) β F1: exploitable β functional, AAS: 9.9 β 11.9 (HIGH β HIGH). Originally in 2026-09-19 bulletin.
- [UPGRADED] CVE-2026-89274 (bootstrapped_ventures/wp_recipe_maker) β F1: exploitable β functional, AAS: 9.4 β 11.4 (HIGH β HIGH). Originally in 2026-09-19 bulletin.
π [HIGH] openclaw/openclaw
2 CVEs | CVSS 4.0: 8.9 | AAS 9.3
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*(>= 2026.4.5, < 2026.8.1)
OpenClaw, an agent gateway distributed as the npm package “openclaw,” is affected by 2 high-severity vulnerabilities, including multiple issues related to DNS pinning bypass in its Chrome DevTools Protocol transport layer. Versions from 2026.4.5 up to but not including 2026.8.1 are vulnerable, with the lead CVE carrying a CVSS 4.0 score of 8.9. An attacker who controls an approved CDP hostname or can manipulate DNS responses can exploit a time-of-check to time-of-use gap between DNS validation and the actual WebSocket connection, enabling DNS rebinding attacks. Teams running OpenClaw in any environment that connects to remote CDP endpoints should upgrade to version 2026.8.1 or later immediately and review the vendor advisory at the link above for additional mitigation guidance.
- π CVE-2026-100567 (CVSS 4.0: 8.9)
- π CVE-2026-100558 (CVSS 4.0: 8.7)