PoC Week 2026-08-31
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-21962 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware 12.2.1.4.0, Oracle Fusion Middleware 14.1.1.0.0, Oracle Fusion Middleware 14.1.2.0.0
- Description: Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in are affected by an improper access control vulnerability that allows an unauthenticated remote attacker to compromise the server. This flaw enables unauthorized access to data and the potential execution of arbitrary commands via the network.
- Remediation:
- More Info: NVD - CVE-2026-21962
- PoC:
CVE-2026-73570 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Zimbra Collaboration (ZCS) versions prior to 10.1.20
- Description: Zimbra Collaboration (ZCS) is affected by an OS command injection vulnerability in its SNMP trap notification handler. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary operating system commands by sending specially crafted SMTP requests.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-73570
- PoC:
CVE-2026-72530 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: TrueConf Server
- Description: TrueConf Server is affected by a sandbox escape and code injection vulnerability in its script execution engine. An unauthenticated remote attacker with network access to TCP port 4307 can execute arbitrary native code on the host operating system.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-72530
- PoC:
CVE-2026-65400
- Severity: 9.8 CRITICAL
- Impacted Products: Apple macOS
- Description: Apple macOS contains an authentication bypass vulnerability in its Screen Sharing component that allows a network-based attacker to authenticate without providing valid credentials. This issue is caused by improper state management during the authentication protocol.
- Remediation:
- More Info: NVD - CVE-2026-65400
- PoC:
CVE-2026-64849 NEW
- Severity: Unknown
- Impacted Products: MLflow, prior to version 3.15.0
- Description: MLflow prior to version 3.15.0 is vulnerable to server-side request forgery (SSRF) in its webhook delivery mechanism. An unauthenticated attacker can exploit this flaw to bypass URL validation and perform unauthorized HTTP requests to internal services and cloud metadata endpoints.
- Remediation:
- More Info: NVD - CVE-2026-64849
- PoC:
CVE-2026-59310
- Severity: 10.0 CRITICAL
- Impacted Products: VMware vCenter Server
- Description: VMware vCenter Server is affected by a directory traversal vulnerability in its Syslog server component that allows remote attackers to access or overwrite arbitrary files. This flaw stems from improper input validation of pathname sequences within the Syslog server message handlers.
- Remediation:
- More Info: NVD - CVE-2026-59310
- PoC:
CVE-2026-55040
- Severity: 9.1 CRITICAL
- Impacted Products: Microsoft SharePoint Server
- Description: Microsoft SharePoint Server is affected by a security feature bypass vulnerability caused by weak authentication within the JWT token validation pipeline. This flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms and perform operations with the privileges of a SharePoint site user or administrator.
- Remediation:
- More Info: NVD - CVE-2026-55040
- PoC:
CVE-2026-48282
- Severity: 9.8 CRITICAL
- Impacted Products: Adobe ColdFusion
- Description: Adobe ColdFusion is affected by a path traversal vulnerability in its Remote Development Services (RDS) component that allows for arbitrary file writes and remote code execution. This flaw enables an unauthenticated attacker to bypass directory restrictions and place malicious files on the host system.
- Remediation:
- More Info: NVD - CVE-2026-48282
- PoC:
CVE-2026-76036 NEW
- Severity: 9.6 CRITICAL
- Impacted Products: Google Chrome
- Description: Google Chrome is affected by a heap-based buffer overflow vulnerability in Dawn, its library implementation for WebGPU. A remote attacker could exploit this flaw to execute arbitrary code outside the browser sandbox by tricking a user into visiting a specially crafted HTML page.
- Remediation:
- More Info: NVD - CVE-2026-76036
- PoC:
CVE-2026-71960 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Cudy WR3000 2.0, firmware before 2.5.24
- Description: Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker’s authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device’s mesh networking interface.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-71960
- PoC:
CVE-2026-67921 NEW
- Severity: 9.3 CRITICAL
- Impacted Products: Halo CMS 2.25.4
- Description: Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-67921
- PoC:
CVE-2026-60004 NEW
- Severity: 8.8 HIGH
- Impacted Products: Gitea
- Description: Gitea is affected by a remote code execution vulnerability in its diff patch handling API endpoint. An authenticated attacker with repository write access can leverage this issue to plant executable Git hooks and run arbitrary shell commands on the hosting server.
- Remediation:
- More Info: NVD - CVE-2026-60004
- PoC:
CVE-2026-22306 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: OzolsSQL before 1.1.1233
- Description: Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N’ActiveScripting') and serv_update.vbs. This issue affects OZOLS: before 1.1.1233.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-22306
- PoC:
CVE-2026-19478 NEW
- Severity: 9.4 CRITICAL
- Impacted Products: GitLab Community Edition 18.2 prior to 18.11.11, GitLab Enterprise Edition 18.2 prior to 18.11.11, GitLab Community Edition 19.0 prior to 19.0.8, GitLab Enterprise Edition 19.0 prior to 19.0.8, GitLab Community Edition 19.1 prior to 19.1.6
- Description: GitLab Community Edition and Enterprise Edition are affected by a code injection vulnerability in GraphQL directive processing. Under certain conditions, an unauthenticated remote attacker can exploit this issue to modify or delete public projects and user data.
- Remediation:
- More Info: NVD - CVE-2026-19478
- PoC:
CVE-2026-18963 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Red Hat Keycloak
- Description: Red Hat Keycloak is affected by a password recovery bypass vulnerability in its keycloak-services component that enables unauthenticated account takeover. An unauthenticated remote attacker can bypass the password reset verification process to reset credentials for any user account.
- Remediation:
- More Info: NVD - CVE-2026-18963
- PoC:
CVE-2020-1938
- Severity: 9.8 CRITICAL
- Impacted Products: Apache Tomcat
- Description: A vulnerability exists within the AJP Connector in Tomcat because the default configuration allows AJP connections to have higher trust and it is also enabled to listen on all configured IP addresses. Apache wrote that the risks were previously documented and they recommended steps to disable the Connector if it wasn’t required.
- Remediation:
- More Info: NVD - CVE-2020-1938
- PoC:
CVE-2026-74936 NEW
- Severity: 8.8 HIGH
- Impacted Products: Mozilla Firefox, Mozilla Thunderbird
- Description: Mozilla Firefox and Mozilla Thunderbird are affected by a use-after-free vulnerability in their JavaScript WebAssembly component. A remote attacker could exploit this flaw by convincing a user to process specially crafted WebAssembly content.
- Remediation:
- More Info: NVD - CVE-2026-74936
- PoC:
CVE-2020-14882 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: WebLogic
- Description: A vulnerability exists within the Console in WebLogic via the .portal endpoint.
- Remediation:
- More Info: NVD - CVE-2020-14882
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.