OpenClaw vs Hermes Agent: Features, Local Models and the Security Record
How OpenClaw and Nous Research's Hermes Agent compare on architecture and local models, plus the major 2026 CVEs and a hardening checklist for both.
Author
Vulnerability analyst
Analyzes exploit development, patch windows, and disclosure timelines.
How OpenClaw and Nous Research's Hermes Agent compare on architecture and local models, plus the major 2026 CVEs and a hardening checklist for both.
Fragnesia, tracked as CVE-2026-46300, is a Linux kernel local privilege escalation flaw involving ESP/IPsec page-cache corruption, with public proof-of-concept code increasing patch urgency.
A high-severity React Server Components denial-of-service flaw can let unauthenticated attackers degrade vulnerable Next.js App Router apps through crafted Server Function requests.
Fortinet patched CVE-2025-32756, a critical unauthenticated RCE flaw exploited against FortiVoice systems for credential theft, FastCGI debugging and network scanning.
Intel issued microcode mitigations for CVE-2024-45332, a Branch Privilege Injection flaw that can bypass Spectre v2 hardware defenses and leak privileged memory from affected systems.
SAP patched CVE-2025-42999, a critical NetWeaver Visual Composer deserialization flaw linked to chained attacks that followed exploitation of CVE-2025-31324.
CVE-2026-42945 is now tracked as a heap-based buffer overflow in NGINX's rewrite module, affecting NGINX Open Source and NGINX Plus under specific rewrite-rule conditions.
Microsoft has disclosed CVE-2026-42897, a high-severity Exchange Server Outlook Web Access vulnerability affecting on-premises deployments, with mitigation available while a permanent fix is pending.