PoC Week 2026-08-31

Posted on Aug 31, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2026-21962 NEW

CVE-2026-73570 NEW

CVE-2026-72530 NEW

  • Severity: 10.0 CRITICAL
  • Impacted Products: TrueConf Server
  • Description: TrueConf Server is affected by a sandbox escape and code injection vulnerability in its script execution engine. An unauthenticated remote attacker with network access to TCP port 4307 can execute arbitrary native code on the host operating system.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-72530
  • PoC:

CVE-2026-65400

CVE-2026-64849 NEW

CVE-2026-59310

CVE-2026-55040

CVE-2026-48282

  • Severity: 9.8 CRITICAL
  • Impacted Products: Adobe ColdFusion
  • Description: Adobe ColdFusion is affected by a path traversal vulnerability in its Remote Development Services (RDS) component that allows for arbitrary file writes and remote code execution. This flaw enables an unauthenticated attacker to bypass directory restrictions and place malicious files on the host system.
  • Remediation:
  • More Info: NVD - CVE-2026-48282
  • PoC:

CVE-2026-76036 NEW

CVE-2026-71960 NEW

  • Severity: 9.1 CRITICAL
  • Impacted Products: Cudy WR3000 2.0, firmware before 2.5.24
  • Description: Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker’s authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device’s mesh networking interface.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-71960
  • PoC:

CVE-2026-67921 NEW

  • Severity: 9.3 CRITICAL
  • Impacted Products: Halo CMS 2.25.4
  • Description: Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-67921
  • PoC:

CVE-2026-60004 NEW

CVE-2026-22306 NEW

  • Severity: 10.0 CRITICAL
  • Impacted Products: OzolsSQL before 1.1.1233
  • Description: Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N’ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-22306
  • PoC:

CVE-2026-19478 NEW

CVE-2026-18963 NEW

CVE-2020-1938

CVE-2026-74936 NEW

CVE-2020-14882 NEW

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.