PoC Week 2026-08-23

Posted on Aug 23, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2026-72898 NEW

CVE-2026-59310 NEW

CVE-2026-18686 NEW

  • Severity: 8.8 HIGH
  • Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
  • Description: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-18686
  • PoC:

CVE-2026-18685 NEW

  • Severity: 8.8 HIGH
  • Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
  • Description: A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-18685
  • PoC:

CVE-2013-4786 NEW

CVE-2026-55040 NEW

CVE-2026-53413 NEW

  • Severity: 8.3 HIGH
  • Impacted Products: Zoom Clients
  • Description: Zoom Clients contains an out-of-bounds write vulnerability within its annotation processing component that allows a meeting participant to execute arbitrary code on another participant’s device. The issue arises from missing bounds checks when parsing shared annotation objects during a meeting.
  • Remediation:
  • More Info: NVD - CVE-2026-53413
  • PoC:

CVE-2026-33824

CVE-2026-9198

CVE-2026-65400 NEW

CVE-2026-42533 NEW

CVE-2026-18577 NEW

CVE-2026-73034 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: DB-GPT v0.8.1
  • Description: DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned user_id header to escape the intended upload directory and write attacker-controlled content to locations such as Python startup hooks, cron directories…
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-73034
  • PoC:

CVE-2026-71362 NEW

CVE-2026-69098 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: kotaemon through 0.12.0
  • Description: kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-69098
  • PoC:

CVE-2026-67870 NEW

  • Severity: 7.5 HIGH
  • Impacted Products: open62541 v1.5.5
  • Description: In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-67870
  • PoC:

CVE-2026-67689 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: FineAdmin V1.0
  • Description: FineAdmin V1.0 is affected by an SQL injection vulnerability in its paginated list endpoints. A remote attacker can exploit this issue via crafted HTTP requests to execute arbitrary SQL commands or code on the system.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-67689
  • PoC:

CVE-2026-58231 NEW

CVE-2026-52680 NEW

CVE-2026-52134 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: libiec61850 v1.6
  • Description: An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-52134
  • PoC:

CVE-2026-51785 NEW

  • Severity: 8.1 HIGH
  • Impacted Products: Hugo Leisink Hiawatha v.12.1 and before
  • Description: An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-51785
  • PoC:

CVE-2026-42530

CVE-2026-38447 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: osTicket 1.18.3
  • Description: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-38447
  • PoC:

CVE-2026-19264 NEW

CVE-2026-18684 NEW

  • Severity: 8.8 HIGH
  • Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
  • Description: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-18684
  • PoC:

CVE-2026-18601 NEW

  • Severity: 8.8 HIGH
  • Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
  • Description: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-18601
  • PoC:

CVE-2026-18108 NEW

CVE-2026-17566 NEW

CVE-2026-17351 NEW

CVE-2024-12856 NEW

CVE-2026-69085 NEW

CVE-2026-69084 NEW

CVE-2026-69083 NEW

CVE-2026-68771 NEW

CVE-2026-67340 NEW

CVE-2026-65321 NEW

CVE-2026-64827 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Telenia Software TVox 26.5.3, Telenia Software TVox 26.x, Telenia Software TVox 24.9.21, Telenia Software TVox 24.x
  • Description: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches ‘login_admin.php’.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-64827
  • PoC:

CVE-2026-63223 NEW

CVE-2026-59243 NEW

CVE-2026-53921 NEW

  • Severity: Unknown
  • Impacted Products: odhcpd, OpenWrt
  • Description: A critical stack overflow vulnerability in the odhcpd DHCPv6 server of OpenWrt. It can be triggered by an unauthenticated attacker sending a crafted DHCPv6 REQUEST to UDP port 547, allowing the attacker to overwrite a stack buffer and execute arbitrary code as root.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-53921
  • PoC:

CVE-2026-50656

CVE-2026-41452 NEW

CVE-2026-33267 NEW

CVE-2025-49113

CVE-2021-33045 NEW

CVE-2021-33044 NEW

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.