
NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 14 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Unauthenticated SQL injection in a low-code app platform — a webhook automation runs attacker SQL against the app's own database, no login (Budibase CVE-2026-72851, CVE-2026-72850, CVE-2026-72853, CVE-2026-72855, CVE-2026-72856, CVE-2026-72857, CVE-2026-72849, CVE-2026-72859, CVE-2026-73302, CVE-2026-73305, CVE-2026-73408) 📦 Signup takeover in a self-hosted file manager — on a case-insensitive filesystem, registering "Admin" lands in the existing admin's home directory (FileBrowser CVE-2026-72836) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #SQLi #CSO #REDTEAM
Post summary
The daily CVE report lists several newly identified vulnerabilities, including unauthenticated SQL injection in Budibase and signup takeover in FileBrowser, but provides no exploit, patch, or PoC information.
