# OpenClaw vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 5 OpenClaw CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 12 tracked threat campaigns and 1 named threat actor.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 OpenClaw CVEs published between 2026-02-15 and 2026-09-15. The busiest month was 2026-07 (3 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked OpenClaw CVEs.

- [CVE-2026-94094](https://intel.threadlinqs.com/cve/CVE-2026-94094) — MEDIUM 4.3 · EPSS 0.3% · 2026-09-20
- [CVE-2026-62195](https://intel.threadlinqs.com/cve/CVE-2026-62195) — HIGH 8.3 · EPSS 0.2% · 2026-07-13
- [CVE-2026-62196](https://intel.threadlinqs.com/cve/CVE-2026-62196) — HIGH 8.3 · EPSS 0.2% · 2026-07-13
- [CVE-2026-62197](https://intel.threadlinqs.com/cve/CVE-2026-62197) — HIGH 8.5 · EPSS 0.2% · 2026-07-13
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253) — HIGH 8.8 · EPSS 0.1% · 2026-02-01

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 1 distinct OpenClaw product is affected. The most frequently affected:

- Openclaw — 5 CVEs

## Threat activity

12 tracked threat campaigns reference OpenClaw products or exploit OpenClaw CVEs:

- [Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquatting](https://intel.threadlinqs.com/threat/TL-2026-1845) — HIGH — 2026-08-03
- [ClawHub Marketplace Skills Expose OpenClaw AI Agents to RCE, Data Theft, and Supply-Chain Backdoors (CVE-2026-25253)](https://intel.threadlinqs.com/threat/TL-2026-1212) — HIGH — 2026-07-11
- [Malicious ClawHub Skills Threaten OpenClaw AI Agent Supply Chain (AMOS, cluw, Solana Front-Running)](https://intel.threadlinqs.com/threat/TL-2026-1024) — HIGH — 2026-07-01
- [OpenClaw / ClawHub AI Skill Marketplace Supply-Chain Compromise — Malicious Skills cluw, AMOS, omnicogg, money-radar, letssendit](https://intel.threadlinqs.com/threat/TL-2026-0921) — HIGH — 2026-06-23
- [AI Skill-Scanner Bypass — ClawHub, Cisco & Vercel Malicious-Skill Detectors Evaded via Truncation, .pyc Bytecode, Archive Indirection & Prompt Injection (Trail of Bits)](https://intel.threadlinqs.com/threat/TL-2026-0702) — HIGH — 2026-06-07
- [OpenClaw Multi-Channel Allowlist Identity-Resolution Bypass — Five Advisories Hijack Trusted AI Agent Access (incl. CVE-2026-28480)](https://intel.threadlinqs.com/threat/TL-2026-0687) — HIGH — 2026-06-06
- [Malicious OpenClaw Skills — AMOS macOS Stealer Supply Chain via ClawHub, SkillsMP, and GitHub](https://intel.threadlinqs.com/threat/TL-2026-0136) — CRITICAL — 2026-02-24
- [OpenClaw AI Agent Framework Security Concerns Prompt Detection Tooling](https://intel.threadlinqs.com/threat/TL-2026-0056) — MEDIUM — 2026-02-03
- [CVE-2026-25253: OpenClaw One-Click RCE via Malicious Link](https://intel.threadlinqs.com/threat/TL-2026-0044) — CRITICAL — 2026-02-03
- [Malicious OpenClaw/MoltBot Skills - 230+ Password-Stealing Packages](https://intel.threadlinqs.com/threat/TL-2026-0043) — HIGH — 2026-02-03
- [Malicious OpenClaw/MoltBot Skills - 230+ Supply Chain Packages](https://intel.threadlinqs.com/threat/TL-2026-0019) — HIGH — 2026-02-02
- [OpenClaw CVE-2026-25253: One-Click RCE via Token Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0008) — HIGH — 2026-02-02

## Threat actors targeting OpenClaw

Named threat actors attributed to campaigns that involve OpenClaw products or CVEs, with the number of linked campaigns:

- [AMOS Operators](https://intel.threadlinqs.com/actor/AMOS%20Operators) — 1 campaign

## How to prioritise OpenClaw patching

This order follows the data Threadlinqs holds for OpenClaw, not a generic severity checklist:

- No OpenClaw CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-94094](https://intel.threadlinqs.com/cve/CVE-2026-94094) (0.3%), [CVE-2026-62195](https://intel.threadlinqs.com/cve/CVE-2026-62195) (0.2%), [CVE-2026-62196](https://intel.threadlinqs.com/cve/CVE-2026-62196) (0.2%).
- 0 CVEs score Critical and 4 High on CVSS v3 (maximum 8.8, average 7.6); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/openclaw
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
