CVE-2026-56702Active Exploitation

MEDIUMCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 2Active Exploitation · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 208-25
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 25 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 📦 Outdated IT service management platform — unauthenticated file deletion reaching code execution (Combodo iTop CVE-2026-39975, CVE-2026-30864, CVE-2026-40877) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🚨 Actively-exploited Oracle web tier — unauthenticated read of critical data straight off the internet-facing front door (Oracle CVE-2026-21962) 📦 Outdated web database console — unauthenticated code execution on the host running it, no login needed (Adminer CVE-2026-56705, CVE-2026-56703, CVE-2026-34968, CVE-2026-56702, CVE-2026-56706, CVE-2026-56704, CVE-2026-34967, CVE-2026-34964, CVE-2026-34959) 📦 Vulnerable Git library pinned in a served manifest — attacker-chosen code runs on the next git command (GitPython CVE-2026-78676, CVE-2026-78677, CVE-2026-78678) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The report details multiple newly disclosed CVEs, noting that Oracle CVE‑2026‑21962 is actively exploited, while providing technical descriptions of each vulnerability but no PoC, exploit tools, patches, or debunking statements.

    0100072
    5 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-56702 (CVSS 8.8) affects Adminer versions before 5.4.3. Review deployments and apply updates if in use. https://nvd.nist.gov/vuln/detail/CVE-2026-56702 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/1ADL8sYHcY

    Post summary

    CVE-2026-56702 is a high‑severity vulnerability in Adminer versions prior to 5.4.3, carrying a CVSS score of 8.8; administrators are urged to review deployments and apply updates.

    0000052
    93 followersView on X

Explore more