PoC Week 2026-07-20

Posted on Jul 20, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2020-1938

CVE-2026-61498 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Vitec Flamingo 4.12.2
  • Description: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-61498
  • PoC:

CVE-2026-60121 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Vitec Flamingo 4.12.2
  • Description: Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-60121
  • PoC:

CVE-2026-56291 NEW

CVE-2026-54998 NEW

CVE-2026-50656

CVE-2026-15410 NEW

  • Severity: 7.2 HIGH
  • Impacted Products: SMA1000 Appliance Management Console
  • Description: Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-15410
  • PoC:

CVE-2026-15409 NEW

CVE-2026-59827 NEW

CVE-2026-59826 NEW

CVE-2026-57830 NEW

  • Severity: 9.1 CRITICAL
  • Impacted Products: Helix Ultimate
  • Description: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-57830
  • PoC:

CVE-2026-56271 NEW

CVE-2026-47729

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.