
NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 13 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🔑 Config endpoint that hands out its session-signing key — anyone who can reach the port mints a valid session and reads every notebook (SiYuan CVE-2026-72793, CVE-2026-72794) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated SCADA/HMI project read — an anonymous request pulls the plant's screens and the addresses of every device behind them (FUXA CVE-2026-47717) ⚡ Sandbox escape in an AI agent builder — code runs on the host holding every model key and DB credential the flows use, and two of them need no login (Flowise CVE-2026-73483, CVE-2026-73485) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM
Post summary
NewNormal Security lists several CVEs with brief technical details about the affected components, but offers no PoC, exploit code, active exploitation evidence, or patch information.
