
NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 20 Sep 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 Missing authorization in a WordPress gallery plugin — any logged-in user reads image records they were never granted, including client proofing sets (NextGEN Gallery CVE-2026-81652, CVE-2026-81654) 📦 PHP object injection over XML-RPC — attacker-chosen classes instantiated inside the site (Forminator CVE-2026-87067) 🔎 Reverse-proxy admin panel now fingerprinted with its release — the box fronting a self-hosted estate appears in the inventory, so advisories against it can be matched (nginx-proxy-manager CVE-2026-93964) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #BrokenAccessControl #CSO #REDTEAM
