Renan Santos[verified]@renandnzsantosPatch
A disclosure of multiple CVEs, summarizing their technical weaknesses and indicating that they were patched with the 2026.2.21 release.
PurpleOps[verified]@PurpleOps_ioPatch
The post announces several high‑CVSS WordPress and OpenClaw vulnerabilities, detailing their technical mechanisms and providing patch/mitigation guidance.
CCB Alert@CCBalertPatch
Seven critical CVEs (CVE-2026-28474, CVE-2026-28466, CVE-2026-28391, CVE-2026-28446, CVE-2026-28470, CVE-2026-28472, CVE-2026-28484) affecting the OpenClaw NextCloud talk plugin are disclosed with CVSS 9.2–9.3; users are advised to update to version 2026.2.6 or later per the vendor advisory.
CVEFind.com@CveFindComDisclosure
The tweet discloses CVE‑2026‑28391, a critical flaw in OpenClaw that bypasses cmd.exe metacharacter checks to allow unauthorized command execution. No proof of concept, exploit, patch, or evidence of active exploitation is mentioned.
0day Signal@0dayPublishingDisclosure
A new vulnerability, CVE-2026-28391, affecting OpenClaw versions prior to 2026.2.2, is disclosed; it involves a classic cmd.exe metacharacter bypass that slips past allow‑list validation, potentially enabling command injection.
CVE@CVEnewDisclosure
The statement announces a vulnerability (CVE-2026-28391) in OpenClaw where improper validation of cmd.exe metacharacters could lead to code execution, but it provides no evidence of PoC, exploit tools, active use, or remediation steps.
The Hacker Wire@TheHackerWireDisclosure
The post discloses a critical vulnerability (CVE‑2026‑28391) in OpenClaw where earlier versions improperly validate Windows cmd.exe metacharacters during allowlist‑gated exec requests, potentially allowing bypass of restrictions.