PoC Week 2026-07-20
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2020-1938
- Severity: 9.8 CRITICAL
- Impacted Products: Apache Tomcat
- Description: A vulnerability exists within the AJP Connector in Tomcat because the default configuration allows AJP connections to have higher trust and it is also enabled to listen on all configured IP addresses. Apache wrote that the risks were previously documented and they recommended steps to disable the Connector if it wasn’t required.
- Remediation:
- More Info: NVD - CVE-2020-1938
- PoC:
CVE-2026-61498 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Vitec Flamingo 4.12.2
- Description: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-61498
- PoC:
CVE-2026-60121 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Vitec Flamingo 4.12.2
- Description: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-60121
- PoC:
CVE-2026-56291 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Balbooa Forms for Joomla
- Description: The Balbooa Forms extension for Joomla is affected by an unauthenticated arbitrary file upload vulnerability that allows for remote code execution. This flaw exists because the extension fails to validate file types or verify user authorization on its frontend upload endpoints.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-56291
- PoC:
CVE-2026-54998 NEW
- Severity: 8.8 HIGH
- Impacted Products: Microsoft Exchange Online
- Description: Microsoft Exchange Online is affected by an incorrect authorization vulnerability that allows a remote, authenticated attacker to escalate their privileges. This flaw exists due to improper validation of access rights when processing requests to Exchange Online APIs.
- Remediation:
- More Info: NVD - CVE-2026-54998
- PoC:
CVE-2026-50656
- Severity: 7.8 HIGH
- Impacted Products: Microsoft Defender
- Description: Microsoft Defender is affected by a race condition vulnerability that allows an attacker to escalate privileges to SYSTEM level. This flaw enables the execution of arbitrary code or unauthorized actions on the affected Windows system.
- Remediation:
- More Info: NVD - CVE-2026-50656
- PoC:
CVE-2026-15410 NEW
- Severity: 7.2 HIGH
- Impacted Products: SMA1000 Appliance Management Console
- Description: Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-15410
- PoC:
CVE-2026-15409 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: SMA1000 Appliance
- Description: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-15409
- PoC:
CVE-2026-59827 NEW
- Severity: 9.9 CRITICAL
- Impacted Products: Metabase 1.58.15, Metabase 1.59.12, Metabase 1.60.6.3, Metabase 1.61.1.4
- Description: Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server.
- Remediation:
- More Info: NVD - CVE-2026-59827
- PoC:
CVE-2026-59826 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Metabase 1.55.0, Metabase 1.58.15.1, Metabase 1.59.12, Metabase 1.60.6.3, Metabase 1.61.2
- Description: Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.
- Remediation:
- More Info: NVD - CVE-2026-59826
- PoC:
CVE-2026-57830 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Helix Ultimate
- Description: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-57830
- PoC:
CVE-2026-56271 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Flowise 3.0.13 and earlier
- Description: Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets (‘auth_token’, ‘refresh_token’) and default audience and issuer values (‘AUDIENCE’, ‘ISSUER’) in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts).
- Remediation:
- More Info: NVD - CVE-2026-56271
- PoC:
CVE-2026-47729
- Severity: 6.5 MEDIUM
- Impacted Products: Squid
- Description: Squid is affected by an out-of-bounds read vulnerability in its FTP gateway component that allows for the disclosure of sensitive information from unrelated transactions. This flaw occurs when a client accesses a malicious or misbehaving FTP server through the Squid gateway.
- Remediation:
- More Info: NVD - CVE-2026-47729
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.