
NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 15 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated AI memory server — everything an assistant was told to remember is readable, and rewritable, by anyone who can reach the port (mcp-memory-service CVE-2026-50027) 🖥️ Unauthenticated database SQL endpoint — arbitrary SELECT, INSERT and DROP on every table, no credential (CrateDB) 🔓 Unfinished CMS installer left reachable — whoever loads the page first picks the admin password and owns the server (WordPress, as seen in Emlog CVE-2026-73849) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #ExposedInterface #CSO #REDTEAM
Post summary
NewNormal Security lists three newly identified CVEs, detailing their unauthenticated read/write and SQL capabilities, but provides no PoC, exploitation code, or patch information.

