PoC Week 2026-07-27
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-63030 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: WordPress 6.9.x before 6.9.5, WordPress 7.0.x before 7.0.2
- Description: WordPress is affected by a REST API batch endpoint route confusion vulnerability that, when chained with a SQL injection flaw, allows unauthenticated remote code execution. This issue impacts WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2.
- Remediation:
- More Info: NVD - CVE-2026-63030
- PoC:
CVE-2026-50522 NEW
- Severity: 8.1 HIGH
- Impacted Products: Microsoft SharePoint Server
- Description: Microsoft SharePoint Server is affected by a deserialization vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code. This flaw exists due to improper validation and cryptographic signature verification when processing session security tokens.
- Remediation:
- More Info: NVD - CVE-2026-50522
- PoC:
CVE-2026-60137 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: WordPress 6.8.x before 6.8.6, WordPress 6.9.x before 6.9.5, WordPress 7.0.x before 7.0.2
- Description: WordPress is affected by an SQL injection vulnerability within the WP_Query class due to insufficient sanitization of the author__not_in parameter. This flaw allows attackers to manipulate database queries when untrusted input is passed to the affected parameter by themes or plugins.
- Remediation:
- More Info: NVD - CVE-2026-60137
- PoC:
CVE-2026-52199 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Generic OEM UZ801_v2.1 4G LTE Router V3.4.3
- Description: An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-52199
- PoC:
CVE-2026-46633 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Twig, prior to 3.26.0
- Description: Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0.
- Remediation:
- More Info: NVD - CVE-2026-46633
- PoC:
CVE-2026-46562 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Yamcs 5.12.7, Yamcs 5.13.0
- Description: Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text.
- Remediation:
- More Info: NVD - CVE-2026-46562
- PoC:
CVE-2026-15410
- Severity: 7.2 HIGH
- Impacted Products: SMA1000 Appliance Management Console
- Description: Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-15410
- PoC:
CVE-2026-15409
- Severity: 10.0 CRITICAL
- Impacted Products: SMA1000 Appliance
- Description: A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-15409
- PoC:
CVE-2021-27137 NEW
- Severity: 8.1 HIGH
- Impacted Products: DD-WRT router firmware versions prior to 45724
- Description: DD-WRT router firmware versions prior to 45724 are affected by a stack-based buffer overflow vulnerability in the UPnP service. An unauthenticated attacker can exploit this flaw by sending a malicious SSDP M-SEARCH request to gain arbitrary code execution or cause a denial of service.
- Remediation:
- More Info: NVD - CVE-2021-27137
- PoC:
CVE-2026-56699 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Wazuh Manager before 5.0.0-beta3
- Description: Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to inject arbitrary NDJSON operations. Attackers can smuggle delete, index, or update operations into bulk requests executed under the manager’s admin credentials, enabling document deletion, alert tampering, and cross-agent SIEM state manipulation.
- Remediation:
- More Info: NVD - CVE-2026-56699
- PoC:
CVE-2026-9198 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Langflow OSS
- Description: Langflow OSS allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-9198
- PoC:
CVE-2026-9103 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Langflow
- Description: Langflow could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unint…
- Remediation:
- More Info: NVD - CVE-2026-9103
- PoC:
CVE-2026-8505 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: IBM Langflow OSS 1.0.0, IBM Langflow OSS 1.1.0, IBM Langflow OSS 1.2.0, IBM Langflow OSS 1.3.0, IBM Langflow OSS 1.4.0
- Description: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow’s webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow’s UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).
- Remediation:
- More Info: NVD - CVE-2026-8505
- PoC:
CVE-2026-6875 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: ServiceNow AI Platform prior to Zurich Patch 9
- Description: ServiceNow AI Platform is affected by a code injection vulnerability that enables unauthenticated remote code execution. This flaw allows an attacker to bypass security restrictions and escape the platform’s sandbox environment.
- Remediation:
- More Info: NVD - CVE-2026-6875
- PoC:
CVE-2026-47729
- Severity: 6.5 MEDIUM
- Impacted Products: Squid
- Description: Squid is affected by an out-of-bounds read vulnerability in its FTP gateway component that allows for the disclosure of sensitive information from unrelated transactions. This flaw occurs when a client accesses a malicious or misbehaving FTP server through the Squid gateway.
- Remediation:
- More Info: NVD - CVE-2026-47729
- PoC:
CVE-2026-0257
- Severity: 9.1 CRITICAL
- Impacted Products: Palo Alto Networks PAN-OS, Prisma Access
- Description: Palo Alto Networks PAN-OS and Prisma Access are affected by an authentication bypass vulnerability in the GlobalProtect portal and gateway components. This flaw allows a remote, unauthenticated attacker to forge authentication cookies and establish unauthorized VPN connections.
- Remediation:
- More Info: NVD - CVE-2026-0257
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.