PoC Week 2026-07-27

Posted on Jul 27, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2026-63030 NEW

CVE-2026-50522 NEW

CVE-2026-60137 NEW

CVE-2026-52199 NEW

  • Severity: 9.1 CRITICAL
  • Impacted Products: Generic OEM UZ801_v2.1 4G LTE Router V3.4.3
  • Description: An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-52199
  • PoC:

CVE-2026-46633 NEW

CVE-2026-46562 NEW

CVE-2026-15410

  • Severity: 7.2 HIGH
  • Impacted Products: SMA1000 Appliance Management Console
  • Description: Post-authentication improper control of generation of code (‘Code Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-15410
  • PoC:

CVE-2026-15409

CVE-2021-27137 NEW

CVE-2026-56699 NEW

CVE-2026-9198 NEW

CVE-2026-9103 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Langflow
  • Description: Langflow could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unint…
  • Remediation:
  • More Info: NVD - CVE-2026-9103
  • PoC:

CVE-2026-8505 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: IBM Langflow OSS 1.0.0, IBM Langflow OSS 1.1.0, IBM Langflow OSS 1.2.0, IBM Langflow OSS 1.3.0, IBM Langflow OSS 1.4.0
  • Description: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow’s webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow’s UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE).
  • Remediation:
  • More Info: NVD - CVE-2026-8505
  • PoC:

CVE-2026-6875 NEW

CVE-2026-47729

CVE-2026-0257

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.