
NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 27 Sep 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 WordPress OTP login plugin authentication bypass — sign in as any administrator with a known username and an empty password (miniOrange CVE-2026-85984) 📤 Unauthenticated arbitrary file upload — drop an executable file into the webroot through a contact form add-on (Ultra Addons for Contact Form 7 CVE-2026-82901) 📦 Database query injection and SSRF in a web radio panel — read the database and reach internal hosts (AzuraCast CVE-2026-100847) 🔎 Hosting control panel fingerprint — Froxlor is now named in the inventory, so advisories against it can match Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #AuthBypass #CSO #REDTEAM
