
NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 2 Oct 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🚨 Mail-gateway path traversal with a NULL-byte bypass — one unauthenticated request writes arbitrary files on the appliance (Fortinet CVE-2026-104286) ⚡ Exposed PHP code generator or debug panel — scaffolding that writes attacker-chosen code into the live webroot, or stored sessions and config served to anyone (Yii CVE-2026-103475) 🔎 Secure file-transfer appliance now fingerprinted — four advisories reachable with no credentials attach to it (Kiteworks CVE-2026-102115, CVE-2026-102147, CVE-2026-102106, CVE-2026-102121) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #PathTraversal #CSO #REDTEAM
