PoC Week 2026-10-11


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-86950 Severity: 8.8 HIGH Impacted Products: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, iOS 27 Description: An out-of-bounds write vulnerability exists in the Apple CoreGraphics framework across iOS, iPadOS, and macOS.…
Read more ⟶

PoC Week 2026-10-04


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-88772 NEW Severity: 9.0 CRITICAL Impacted Products: Citrix NetScaler ADC, Citrix NetScaler Gateway Description: Citrix NetScaler ADC and NetScaler Gateway are affected by a memory overflow vulnerability within the Datagram Transport Layer Security (DTLS) packet handling subsystem.…
Read more ⟶

PoC Week 2026-09-27


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-21962 Severity: 10.0 CRITICAL Impacted Products: Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware 12.2.1.4.0, Oracle Fusion Middleware 14.…
Read more ⟶

PoC Week 2026-09-21


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-21962 Severity: 10.0 CRITICAL Impacted Products: Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware 12.2.1.4.0, Oracle Fusion Middleware 14.…
Read more ⟶

PoC Week 2026-09-13


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-9586 NEW Severity: 9.8 CRITICAL Impacted Products: Sangoma Switchvox SMB Edition versions prior to 8.4.0.2 Description: Sangoma Switchvox SMB Edition is affected by an unauthenticated SQL injection vulnerability in its phone application and provisioning subsystem.…
Read more ⟶

PoC Week 2026-09-06


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-8452 Severity: 9.8 CRITICAL Impacted Products: NetScaler ADC, NetScaler Gateway Description: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server Remediation: Follow vendor security advisories and apply the latest patches.…
Read more ⟶

PoC Week 2026-08-31


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-21962 NEW Severity: 10.0 CRITICAL Impacted Products: Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware 12.2.1.4.0, Oracle Fusion Middleware 14.…
Read more ⟶

PoC Week 2026-08-23


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-72898 NEW Severity: 10.0 CRITICAL Impacted Products: Metabase Description: Metabase is affected by an unauthenticated SQL injection vulnerability in its password reset functionality.…
Read more ⟶

PoC Week 2026-07-27


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2026-63030 NEW Severity: 9.8 CRITICAL Impacted Products: WordPress 6.9.x before 6.9.5, WordPress 7.0.x before 7.0.2 Description: WordPress is affected by a REST API batch endpoint route confusion vulnerability that, when chained with a SQL injection flaw, allows unauthenticated remote code execution.…
Read more ⟶

PoC Week 2026-07-20


The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count. For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution. CVE-2020-1938 Severity: 9.8 CRITICAL Impacted Products: Apache Tomcat Description: A vulnerability exists within the AJP Connector in Tomcat because the default configuration allows AJP connections to have higher trust and it is also enabled to listen on all configured IP addresses.…
Read more ⟶