PoC Week 2026-09-06
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-8452
- Severity: 9.8 CRITICAL
- Impacted Products: NetScaler ADC, NetScaler Gateway
- Description: Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-8452
- PoC:
CVE-2026-82078 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: PaperCut MF, PaperCut NG
- Description: PaperCut MF and PaperCut NG are affected by an unsafe dynamic class loading vulnerability in their database connector utilities. An attacker with the ability to modify application configuration settings can leverage this flaw to execute arbitrary code on the underlying server.
- Remediation:
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut
- Add exploit module for the recent PaperCut MF/NG 0day (CVE-2026-81578 + CVE-2026-82078) by sfewer-r7 · Pull Request #21842 · rapid7/metasploit-framework · GitHub
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078
- More Info: NVD - CVE-2026-82078
- PoC:
CVE-2026-81578 NEW
- Severity: 8.6 HIGH
- Impacted Products: PaperCut MF, PaperCut NG
- Description: PaperCut MF and PaperCut NG are affected by an authentication bypass vulnerability in their web management interface. An unauthenticated remote attacker can exploit this flaw to execute privileged administrative actions and alter system configurations without authenticating.
- Remediation:
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut
- Add exploit module for the recent PaperCut MF/NG 0day (CVE-2026-81578 + CVE-2026-82078) by sfewer-r7 · Pull Request #21842 · rapid7/metasploit-framework · GitHub
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578
- More Info: NVD - CVE-2026-81578
- PoC:
CVE-2026-66384 NEW
- Severity: 5.3 MEDIUM
- Impacted Products: JFrog Artifactory
- Description: JFrog Artifactory is affected by a path traversal vulnerability in its container and Docker remote repository caching service. This flaw allows an authenticated remote user to write data outside of the intended cache directory on the host filesystem.
- Remediation:
- More Info: NVD - CVE-2026-66384
- PoC:
CVE-2026-60004
- Severity: 8.8 HIGH
- Impacted Products: Gitea
- Description: Gitea is affected by a remote code execution vulnerability in its diff patch handling API endpoint. An authenticated attacker with repository write access can leverage this issue to plant executable Git hooks and run arbitrary shell commands on the hosting server.
- Remediation:
- More Info: NVD - CVE-2026-60004
- PoC:
CVE-2026-48282
- Severity: 9.8 CRITICAL
- Impacted Products: Adobe ColdFusion
- Description: Adobe ColdFusion is affected by a path traversal vulnerability in its Remote Development Services (RDS) component that allows for arbitrary file writes and remote code execution. This flaw enables an unauthenticated attacker to bypass directory restrictions and place malicious files on the host system.
- Remediation:
- More Info: NVD - CVE-2026-48282
- PoC:
CVE-2022-0995 NEW
- Severity: 7.1 HIGH
- Impacted Products: Linux kernel
- Description: An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
- Remediation:
- More Info: NVD - CVE-2022-0995
- PoC:
CVE-2021-23758 NEW
- Severity: 8.1 HIGH
- Impacted Products: ajaxpro.2
- Description: The ajaxpro.2 package for .NET is vulnerable to deserialization of untrusted data. An attacker can exploit this issue by supplying crafted input to deserialize arbitrary .NET classes, allowing for remote code execution.
- Remediation:
- More Info: NVD - CVE-2021-23758
- PoC:
CVE-2015-5287 NEW
- Severity: 7.8 HIGH
- Impacted Products: Automatic Bug Reporting Tool (ABRT) prior to version 2.7.1
- Description: Automatic Bug Reporting Tool (ABRT) contains an insecure symbolic link handling vulnerability within its kernel-invoked core dump processing component. A local attacker can exploit this flaw to escalate privileges on the target system.
- Remediation:
- More Info: NVD - CVE-2015-5287
- PoC:
CVE-2015-3246 NEW
- Severity: 5.1 MEDIUM
- Impacted Products: libuser before 0.56.13-8, libuser 0.60 before 0.60-7, usermode package
- Description: libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
- Remediation:
- More Info: NVD - CVE-2015-3246
- PoC:
CVE-2026-81735 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: mcp-http-server@1.2.4, @agent-infra/mcp-server-commands, @agent-infra/mcp-server-filesystem
- Description: startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to ‘::’ when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a caller supplies them. The @agent-infra/mcp-server-commands and @agent-infra/mcp-server-filesystem entry points call startSseAndStreamableHttpMcpServer with a host and port alone an…
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-81735
- PoC:
CVE-2026-80428 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: ILIAS before versions 9.22, 10.10, 11.3
- Description: ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint’s unrestricted deserialization to writ…
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-80428
- PoC:
CVE-2026-75325 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: DWSurvey v6.14.0
- Description: DWSurvey v6.14.0 is is vulnerable to authentication bypass via the ‘/api/dwsurvey/none/’ and ‘/api/dwsurvey/up/**’ parameters.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-75325
- PoC:
CVE-2026-74233 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Zbtlink MQWrt router firmware
- Description: Zbtlink MQWrt router firmware across multiple hardware models is vulnerable to unauthenticated command injection within its management service. This flaw allows a remote attacker to execute arbitrary shell commands on affected devices without valid credentials.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-74233
- PoC:
CVE-2026-56705 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Adminer before 5.4.3
- Description: Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.
- Remediation:
- More Info: NVD - CVE-2026-56705
- PoC:
CVE-2026-37006 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: gpt-researcher 0.14.7 and earlier
- Description: gpt-researcher version 0.14.7 and earlier is vulnerable to remote code execution due to improper authentication and unsanitized command execution within its WebSocket endpoint. An unauthenticated remote attacker can exploit this flaw by sending a malicious Model Context Protocol configuration to execute arbitrary code on the underlying host system.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-37006
- PoC:
CVE-2026-37004 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: BerriAI LiteLLM 1.82.4 and earlier
- Description: BerriAI LiteLLM versions 1.82.4 and earlier are vulnerable to Server-Side Template Injection (SSTI) within the /prompts/test endpoint. An unauthenticated remote attacker can exploit this flaw to execute arbitrary operating system commands on the host server.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-37004
- PoC:
CVE-2026-37003 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Agno up to and including 2.5.8, PythonTools, ShellTools
- Description: Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execution sinks including exec(), runpy.run_path(), and subprocess.run(). An unauthenticated attacker can exploit this by embedding malicious instructions in content processed by the agent (such as web pages or documents), allowing for arbitrary code and OS command execution on the host server.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-37003
- PoC:
CVE-2026-19912 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Kaltura HTML5 player
- Description: Kaltura HTML5 player (mwEmbed / html5lib) is affected by an unauthenticated remote code execution vulnerability caused by unsafe PHP deserialization and improper path sanitization. An attacker can leverage this flaw to write arbitrary files into web-accessible directories, leading to remote code execution.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-19912
- PoC:
CVE-2019-14287 NEW
- Severity: 7.0 HIGH
- Impacted Products: Sudo
- Description: A vulnerability exists within special configurations of Sudo in which users are allowed to run commands as an arbitrary user, specified by the ‘ALL’ keyword in the ‘Runas’ specifier in the user’s sudoers entry.
- Remediation:
- More Info: NVD - CVE-2019-14287
- PoC:
CVE-2026-82329 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: JFrog Artifactory
- Description: JFrog Artifactory contains an improper authentication vulnerability that allows unauthenticated remote attackers to bypass security controls. Under default configurations, an attacker with network access to the web interface or API can obtain full administrative privileges.
- Remediation:
- More Info: NVD - CVE-2026-82329
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.