
NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 3 Oct 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🕳️ Configuration export archive left downloadable — the whole settings tree, role matrix and stored API keys, read with no login (Backdrop CMS CVE-2026-104476) 📦 OpenPGP and MLS signature bindings accepted without proof — a signing subkey with no back-signature verifies anyway (Bouncy Castle CVE-2026-71885) 📦 Worker pool runs whatever module its caller's options object names — a request-shaped options bag picks the file a worker executes (Tinypool CVE-2026-104849) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #DataExposure #CSO #REDTEAM
