
NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 7 Oct 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📂 Pre-auth arbitrary file read — the server returns its own deployment descriptor, then the config and credentials beside it, with no login (Atlassian CVE-2026-21589) 📦 Plugin writing a credential to a world-readable log — the shipping carrier's API key, and with it the power to change order statuses (Geliver CVE-2026-103378) 📦 REST routes registered with no permission check — unpublished store records read anonymously (WPCafe CVE-2026-86816) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #PathTraversal #CSO #REDTEAM
