PoC Week 2026-08-23
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-72898 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Metabase
- Description: Metabase is affected by an unauthenticated SQL injection vulnerability in its password reset functionality. An unauthenticated remote attacker can exploit this issue to execute arbitrary SQL queries and gain administrator access to the application.
- Remediation:
- More Info: NVD - CVE-2026-72898
- PoC:
CVE-2026-59310 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: VMware vCenter Server
- Description: VMware vCenter Server is affected by a directory traversal vulnerability in its Syslog server component that allows remote attackers to access or overwrite arbitrary files. This flaw stems from improper input validation of pathname sequences within the Syslog server message handlers.
- Remediation:
- More Info: NVD - CVE-2026-59310
- PoC:
CVE-2026-18686 NEW
- Severity: 8.8 HIGH
- Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
- Description: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-18686
- PoC:
CVE-2026-18685 NEW
- Severity: 8.8 HIGH
- Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
- Description: A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-18685
- PoC:
CVE-2013-4786 NEW
- Severity: 7.5 HIGH
- Impacted Products: IMPI version 2.0
- Description: Intelligent Platform Management Protocol is a industry-wide protocol used to standardize hardware-based remote server management. Baseboard Management Controllers (BMC) are commonly designed using IPMI.
- Remediation:
- More Info: NVD - CVE-2013-4786
- PoC:
CVE-2026-55040 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Microsoft SharePoint Server
- Description: Microsoft SharePoint Server is affected by a security feature bypass vulnerability caused by weak authentication within the JWT token validation pipeline. This flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms and perform operations with the privileges of a SharePoint site user or administrator.
- Remediation:
- More Info: NVD - CVE-2026-55040
- PoC:
CVE-2026-53413 NEW
- Severity: 8.3 HIGH
- Impacted Products: Zoom Clients
- Description: Zoom Clients contains an out-of-bounds write vulnerability within its annotation processing component that allows a meeting participant to execute arbitrary code on another participant’s device. The issue arises from missing bounds checks when parsing shared annotation objects during a meeting.
- Remediation:
- More Info: NVD - CVE-2026-53413
- PoC:
CVE-2026-33824
- Severity: 9.8 CRITICAL
- Impacted Products: Microsoft Windows, IKE version 2 (IKEv2)
- Description: Microsoft Windows is affected by a double free vulnerability in the Internet Key Exchange (IKE) Service Extensions that allows for remote code execution. An unauthenticated attacker can trigger this flaw by sending specially crafted packets to a target system where IKE version 2 (IKEv2) is enabled.
- Remediation:
- More Info: NVD - CVE-2026-33824
- PoC:
CVE-2026-9198
- Severity: 9.8 CRITICAL
- Impacted Products: Langflow OSS
- Description: Langflow OSS allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-9198
- PoC:
CVE-2026-65400 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Apple macOS
- Description: Apple macOS contains an authentication bypass vulnerability in its Screen Sharing component that allows a network-based attacker to authenticate without providing valid credentials. This issue is caused by improper state management during the authentication protocol.
- Remediation:
- More Info: NVD - CVE-2026-65400
- PoC:
CVE-2026-42533 NEW
- Severity: 8.1 HIGH
- Impacted Products: NGINX Plus, NGINX Open Source
- Description: NGINX Plus and NGINX Open Source are affected by a heap-based buffer overflow vulnerability within the map directive component. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests, potentially leading to a denial-of-service or arbitrary code execution.
- Remediation:
- More Info: NVD - CVE-2026-42533
- PoC:
CVE-2026-18577 NEW
- Severity: 6.8 MEDIUM
- Impacted Products: N-able N-central 2026.3.1
- Description: N-able N-central is affected by an authentication bypass vulnerability resulting from an incomplete patch for CVE-2026-18556. This flaw allows a remote, unauthenticated attacker to bypass authentication controls and achieve complete administrative account takeover on vulnerable systems.
- Remediation:
- More Info: NVD - CVE-2026-18577
- PoC:
CVE-2026-73034 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: DB-GPT v0.8.1
- Description: DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned user_id header to escape the intended upload directory and write attacker-controlled content to locations such as Python startup hooks, cron directories…
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-73034
- PoC:
CVE-2026-71362 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Adobe Commerce
- Description: Adobe Commerce is affected by an incorrect authorization vulnerability that allows a remote attacker to escalate privileges. An attacker can exploit this issue without requiring user interaction to gain unauthorized access to sensitive resources.
- Remediation:
- More Info: NVD - CVE-2026-71362
- PoC:
CVE-2026-69098 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: kotaemon through 0.12.0
- Description: kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-69098
- PoC:
CVE-2026-67870 NEW
- Severity: 7.5 HIGH
- Impacted Products: open62541 v1.5.5
- Description: In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-67870
- PoC:
CVE-2026-67689 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: FineAdmin V1.0
- Description: FineAdmin V1.0 is affected by an SQL injection vulnerability in its paginated list endpoints. A remote attacker can exploit this issue via crafted HTTP requests to execute arbitrary SQL commands or code on the system.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-67689
- PoC:
CVE-2026-58231 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: SAP Commerce Cloud (versions COM_CLOUD 2211, 2211-JDK21)
- Description: SAP Commerce Cloud is affected by an improper authorization and code injection vulnerability within its Data Hub Adapter component. An unauthenticated remote attacker can abuse a default authentication client and submit crafted payloads to execute arbitrary code on the underlying system.
- Remediation:
- More Info: NVD - CVE-2026-58231
- PoC:
CVE-2026-52680 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Apache Kyuubi: from 1.7.0 through 1.11.1, Apache Kyuubi: 1.12.0
- Description: Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended to upgrade to versi…
- Remediation:
- More Info: NVD - CVE-2026-52680
- PoC:
CVE-2026-52134 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: libiec61850 v1.6
- Description: An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-52134
- PoC:
CVE-2026-51785 NEW
- Severity: 8.1 HIGH
- Impacted Products: Hugo Leisink Hiawatha v.12.1 and before
- Description: An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-51785
- PoC:
CVE-2026-42530
- Severity: 8.1 HIGH
- Impacted Products: NGINX Open Source
- Description: NGINX Open Source is affected by a use-after-free vulnerability in the ngx_http_v3_module when configured to use the HTTP/3 QUIC module. A remote, unauthenticated attacker, along with conditions beyond their control, can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream, potentially leading to a denial of service or arbitrary code execution.
- Remediation:
- More Info: NVD - CVE-2026-42530
- PoC:
CVE-2026-38447 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: osTicket 1.18.3
- Description: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-38447
- PoC:
CVE-2026-19264 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Postiz
- Description: Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded only once they reach the handler, restoring the traversal at the filesystem call. An unauthenticated…
- Remediation:
- More Info: NVD - CVE-2026-19264
- PoC:
CVE-2026-18684 NEW
- Severity: 8.8 HIGH
- Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
- Description: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-18684
- PoC:
CVE-2026-18601 NEW
- Severity: 8.8 HIGH
- Impacted Products: GL.iNet GL-MT3000 up to 4.4.5
- Description: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-18601
- PoC:
CVE-2026-18108 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Net::SAML2 versions before 0.86
- Description: Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature.
- Remediation:
- More Info: NVD - CVE-2026-18108
- PoC:
CVE-2026-17566 NEW
- Severity: 9.9 CRITICAL
- Impacted Products: pgAdmin 4 prior to version 9.18
- Description: pgAdmin 4 is affected by an OS command injection vulnerability in its Import/Export Data tool prior to version 9.18. A logic mismatch in string escape validation allows authenticated attackers to bypass query guards and execute arbitrary commands on the underlying host.
- Remediation:
- More Info: NVD - CVE-2026-17566
- PoC:
CVE-2026-17351 NEW
- Severity: 9.0 CRITICAL
- Impacted Products: pgAdmin 4 9.13, pgAdmin 4 9.14, pgAdmin 4 9.15, pgAdmin 4 9.16
- Description: pgAdmin 4 is affected by an SQL injection and read-only transaction bypass vulnerability in its AI Assistant feature. This issue arises from a lexer parsing disagreement between the sqlparse library and PostgreSQL, enabling crafted SQL queries to bypass validation checks.
- Remediation:
- More Info: NVD - CVE-2026-17351
- PoC:
CVE-2024-12856 NEW
- Severity: 7.2 HIGH
- Impacted Products: Four-Faith F3x24 firmware version 2.0, Four-Faith F3x36 firmware version 2.0
- Description: Four-Faith router models F3x24 and F3x36 are affected by an OS command injection vulnerability in firmware version 2.0, allowing authenticated remote attackers to execute arbitrary OS commands via the
apply.cgiinterface when modifying system time. The presence of default credentials can effectively render this vulnerability unauthenticated. - Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2024-12856
- PoC:
CVE-2026-69085 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: SiYuan v3.7.3
- Description: SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding.
- Remediation:
- More Info: NVD - CVE-2026-69085
- PoC:
CVE-2026-69084 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: SiYuan v3.7.2
- Description: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions.
- Remediation:
- More Info: NVD - CVE-2026-69084
- PoC:
CVE-2026-69083 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: SiYuan v3.7.3
- Description: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.
- Remediation:
- More Info: NVD - CVE-2026-69083
- PoC:
CVE-2026-68771 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: ComfyUI v0.23.0
- Description: ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code.
- Remediation:
- More Info: NVD - CVE-2026-68771
- PoC:
CVE-2026-67340 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: ArcadeDB before 26.7.2
- Description: ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires.
- Remediation:
- More Info: NVD - CVE-2026-67340
- PoC:
CVE-2026-65321 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: PyAthena < 3.35.4, Athena, Trino
- Description: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL s…
- Remediation:
- More Info: NVD - CVE-2026-65321
- PoC:
CVE-2026-64827 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Telenia Software TVox 26.5.3, Telenia Software TVox 26.x, Telenia Software TVox 24.9.21, Telenia Software TVox 24.x
- Description: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches ‘login_admin.php’.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-64827
- PoC:
CVE-2026-63223 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: CodeIgniter 4.7.4
- Description: CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory.
- Remediation:
- More Info: NVD - CVE-2026-63223
- PoC:
CVE-2026-59243 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: apache-airflow-providers-fab < 3.7.3
- Description: The apache-airflow-providers-fab package prior to version 3.7.3 is affected by an authentication bypass vulnerability in its FAB auth manager component. An unauthenticated attacker can exploit this flaw to bypass authentication and log in as any arbitrary user, including accounts with administrative privileges.
- Remediation:
- CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (
verify_signaturedefaults toFalse)-Apache Mail Archives - Verify Azure AD OAuth id_token signatures by default in FAB auth manager by potiuk · Pull Request #69374 · apache/airflow · GitHub
- CVE-2026-59243: Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (
- More Info: NVD - CVE-2026-59243
- PoC:
CVE-2026-53921 NEW
- Severity: Unknown
- Impacted Products: odhcpd, OpenWrt
- Description: A critical stack overflow vulnerability in the odhcpd DHCPv6 server of OpenWrt. It can be triggered by an unauthenticated attacker sending a crafted DHCPv6 REQUEST to UDP port 547, allowing the attacker to overwrite a stack buffer and execute arbitrary code as root.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-53921
- PoC:
CVE-2026-50656
- Severity: 7.8 HIGH
- Impacted Products: Microsoft Defender
- Description: Microsoft Defender is affected by a race condition vulnerability that allows an attacker to escalate privileges to SYSTEM level. This flaw enables the execution of arbitrary code or unauthorized actions on the affected Windows system.
- Remediation:
- More Info: NVD - CVE-2026-50656
- PoC:
CVE-2026-41452 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Krayin CRM 2.2.4
- Description: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-41452
- PoC:
CVE-2026-33267 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Apache Traffic Server 9.2.0 through 9.2.14, Apache Traffic Server 10.1.0 through 10.1.3
- Description: Apache Traffic Server is affected by an improper input validation vulnerability that allows remote attackers to spoof internal metadata. The flaw exists because the server fails to sanitize untrusted internal and hop-by-hop headers from incoming HTTP requests.
- Remediation:
- More Info: NVD - CVE-2026-33267
- PoC:
CVE-2025-49113
- Severity: 9.9 CRITICAL
- Impacted Products: Roundcube Webmail
- Description: Roundcube Webmail is affected by a PHP object deserialization vulnerability that allows authenticated users to execute arbitrary code. This flaw exists because the application fails to properly validate the
_fromURL parameter within theprogram/actions/settings/upload.phpcomponent. - Remediation:
- More Info: NVD - CVE-2025-49113
- PoC:
CVE-2021-33045 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Dahua IP cameras
- Description: Dahua IP cameras and related products are affected by an authentication bypass vulnerability in the login component. By sending specially crafted network packets, a remote attacker can circumvent identity verification to gain unauthorized access to the device.
- Remediation:
- More Info: NVD - CVE-2021-33045
- PoC:
CVE-2021-33044 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Dahua IP cameras, Dahua video intercoms
- Description: Multiple Dahua products, including IP cameras and video intercoms, are affected by an authentication bypass vulnerability. This flaw allows a remote attacker to bypass identity verification by sending specially crafted data packets during the login process.
- Remediation:
- More Info: NVD - CVE-2021-33044
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.