
NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 25 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 📦 Outdated IT service management platform — unauthenticated file deletion reaching code execution (Combodo iTop CVE-2026-39975, CVE-2026-30864, CVE-2026-40877) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🚨 Actively-exploited Oracle web tier — unauthenticated read of critical data straight off the internet-facing front door (Oracle CVE-2026-21962) 📦 Outdated web database console — unauthenticated code execution on the host running it, no login needed (Adminer CVE-2026-56705, CVE-2026-56703, CVE-2026-34968, CVE-2026-56702, CVE-2026-56706, CVE-2026-56704, CVE-2026-34967, CVE-2026-34964, CVE-2026-34959) 📦 Vulnerable Git library pinned in a served manifest — attacker-chosen code runs on the next git command (GitPython CVE-2026-78676, CVE-2026-78677, CVE-2026-78678) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM
Post summary
The post highlights an actively exploited Oracle CVE (CVE‑2026‑21962) along with other newly reported vulnerabilities, but does not provide PoC or patch information.

