PurpleOps[verified]@PurpleOps_ioDisclosure
The post details multiple high‑CVSS vulnerabilities across WordPress themes and OpenClaw, provides technical specifics and patch guidance, but does not include PoC, exploit code, or evidence of active exploitation.
CCB Alert@CCBalertPatch
Seven critical vulnerabilities in the OpenClaw NextCloud Talk plugin have been disclosed; users are advised to update to version 2026.2.6 or later to mitigate the CVEs.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2026‑28470 in OpenClaw, showing a command‑substitution technique that bypasses the exec allowlist, effectively disclosing the vulnerability and demonstrating a proof‑of‑concept.
CVE@CVEnewDisclosure
The note announces that OpenClaw versions before 2026.2.2 have an allowlist bypass allowing arbitrary command execution, but provides no PoC, patch, or exploit details.
VulDB 🛡@vuldbDisclosure
The statement announces that a new vulnerability, CVE-2026-28470, targeting OpenClaw has been disclosed with higher severity, referencing a VulDB entry.
The Hacker Wire@TheHackerWireDisclosure
The tweet discloses a critical vulnerability (CVE‑2026‑28470) in OpenClaw that allows arbitrary command execution via an allowlist bypass, but provides no proof of concept, exploit code, or mitigation.
CVEFind.com@CveFindComDisclosure
The text announces a critical vulnerability (CVE‑2026‑28470) in OpenClaw versions before 2026.2.2, describing an allowlist bypass that permits attackers to execute unauthorized commands through command substitution.