
NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 25 Sep 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🖥️ Unauthenticated MCP server — whoever finds the port drives its tools, as seen in DBHub CVE-2026-61742 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🕳️ Unauthenticated runtime-config endpoint — the whole server config read anonymously, admin email included, as seen in OpenObserve CVE-2026-63645 🖥️ Container log viewer with auth switched off — live logs of every container on the host: tokens, connection strings, reset links (Dozzle) 📦 WooCommerce reviews plugin with no permission check — a visitor does what the storefront reserves for staff (CVE-2026-89055) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #InfoDisclosure #CSO #REDTEAM
