
NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 15 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated AI memory server — everything an assistant was told to remember is readable, and rewritable, by anyone who can reach the port (mcp-memory-service CVE-2026-50027) 🖥️ Unauthenticated database SQL endpoint — arbitrary SELECT, INSERT and DROP on every table, no credential (CrateDB) 🔓 Unfinished CMS installer left reachable — whoever loads the page first picks the admin password and owns the server (WordPress, as seen in Emlog CVE-2026-73849) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #ExposedInterface #CSO #REDTEAM
Post summary
The post announces three newly discovered CVEs with brief technical details of each vulnerability but does not disclose PoCs, exploits, patches, or evidence of active exploitation.

