CVE-2026-25253
CVSS 8.8 HIGH: openClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically… EPSS 24% (98th percentile).
AI · 155 days ago
Autonomous AI agents on enterprise servers create operational risks that isolated security signals often miss. An unauthorized OpenClaw AI agent was found on a Windows Server, but only by correlating endpoint, exposure, and identity telemetry did it become clear this was a high-priority threat. This shows that visibility alone is insufficient; understanding what the software can enable is critical.
Qualys Enterprise TruRisk Management (ETM) combined data from Qualys VMDR, Microsoft Defender Vulnerability Management, Qualys EASM, and identity signals to identify a reachable autonomous AI agent with real attack paths. Each signal alone appeared low priority, but their correlation revealed active risk requiring immediate attention. This demonstrates the power of contextual correlation in risk operations centers.
As autonomous AI agents become more common, attackers or unauthorized users could leverage them to establish persistent communication, expose services, or execute commands with elevated permissions. Without correlating diverse telemetry sources, these risks remain hidden. The forward risk is that enterprises must evolve detection beyond isolated alerts to integrated risk analysis to catch emerging AI-powered threats.
CVSS 8.8 HIGH: openClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically… EPSS 24% (98th percentile).
1 source covering this story
Anatomy of an Autonomous AI Agent Risk: Qualys ETM on OpenClaw | Qualys
In this OpenClaw investigation, ETM correlates VMDR, Microsoft Defender, EASM, and identity risks to reveal a reachable autonomous AI agent with real attack paths.
Part of the PlainSec briefing for 2026-04-14