PoC Week 2026-09-13

Posted on Sep 13, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2026-9586 NEW

CVE-2026-86218 NEW

CVE-2026-85046 NEW

CVE-2026-83549 NEW

  • Severity: 7.2 HIGH
  • Impacted Products: SonicWall Secure Mobile Access (SMA) 1000 Series
  • Description: SonicWall Secure Mobile Access (SMA) 1000 Series appliances contain an OS command injection vulnerability in the Appliance Management Console (AMC). An authenticated remote administrator can exploit this vulnerability to execute arbitrary operating system commands on the device.
  • Remediation:
  • More Info: NVD - CVE-2026-83549
  • PoC:

CVE-2026-83548 NEW

CVE-2026-82329

CVE-2026-59822 NEW

CVE-2026-49869 NEW

CVE-2026-85696 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: SadTalker
  • Description: SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-85696
  • PoC:

CVE-2026-85688 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: TEN Framework 0.11.71
  • Description: TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-85688
  • PoC:

CVE-2026-85672 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: zerox 1.1.20
  • Description: zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occurs.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-85672
  • PoC:

CVE-2026-75604 NEW

CVE-2026-44402 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Voltronic Power SNMP Web Pro 1.1
  • Description: Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-44402
  • PoC:

CVE-2026-20212 NEW

CVE-2025-31200

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.