PoC Week 2026-09-13
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-9586 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Sangoma Switchvox SMB Edition versions prior to 8.4.0.2
- Description: Sangoma Switchvox SMB Edition is affected by an unauthenticated SQL injection vulnerability in its phone application and provisioning subsystem. A remote attacker can exploit this issue to achieve arbitrary code execution on the underlying PBX appliance.
- Remediation:
- More Info: NVD - CVE-2026-9586
- PoC:
CVE-2026-86218 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: N-able N-central
- Description: N-able N-central is affected by a static code injection vulnerability that allows an unauthenticated remote attacker to achieve arbitrary code execution on the server.
- Remediation:
- More Info: NVD - CVE-2026-86218
- PoC:
CVE-2026-85046 NEW
- Severity: 8.8 HIGH
- Impacted Products: Google Chrome prior to version 152.0.7977.82
- Description: Google Chrome is affected by a type confusion vulnerability within its V8 JavaScript and WebAssembly engine prior to version 152.0.7977.82. An unauthenticated remote attacker can exploit this flaw by convincing a user to view a specially crafted HTML page.
- Remediation:
- More Info: NVD - CVE-2026-85046
- PoC:
CVE-2026-83549 NEW
- Severity: 7.2 HIGH
- Impacted Products: SonicWall Secure Mobile Access (SMA) 1000 Series
- Description: SonicWall Secure Mobile Access (SMA) 1000 Series appliances contain an OS command injection vulnerability in the Appliance Management Console (AMC). An authenticated remote administrator can exploit this vulnerability to execute arbitrary operating system commands on the device.
- Remediation:
- More Info: NVD - CVE-2026-83549
- PoC:
CVE-2026-83548 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: SonicWall Secure Mobile Access (SMA) 1000 Series
- Description: SonicWall Secure Mobile Access (SMA) 1000 Series appliances contain a pre-authentication server-side request forgery (SSRF) vulnerability in the Work Place web interface. An unauthenticated remote attacker can exploit this issue to force the appliance to act as a proxy and route arbitrary network traffic to internal subnets or local loopback interfaces.
- Remediation:
- More Info: NVD - CVE-2026-83548
- PoC:
CVE-2026-82329
- Severity: 10.0 CRITICAL
- Impacted Products: JFrog Artifactory
- Description: JFrog Artifactory contains an improper authentication vulnerability that allows unauthenticated remote attackers to bypass security controls. Under default configurations, an attacker with network access to the web interface or API can obtain full administrative privileges.
- Remediation:
- More Info: NVD - CVE-2026-82329
- PoC:
CVE-2026-59822 NEW
- Severity: 8.2 HIGH
- Impacted Products: LiteLLM prior to version 1.84.0
- Description: LiteLLM prior to version 1.84.0 contains an improper authentication vulnerability in its Model Context Protocol (MCP) streamable HTTP endpoints. An unauthenticated remote attacker can exploit this flaw using a fabricated Authorization header to bypass authentication controls and gain access to protected backend tools and models.
- Remediation:
- https://github.com/BerriAI/litellm/commit/73869f0faf7d11ee21adcb5f91b8c33a340b6c2c
- fix(mcp): tighten public-route detection and OAuth2 fallback gating by stuxf · Pull Request #26463 · BerriAI/litellm · GitHub
- MCP Authentication Bypass via OAuth2 Passthrough Fallback · Advisory · BerriAI/litellm · GitHub
- More Info: NVD - CVE-2026-59822
- PoC:
CVE-2026-49869 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Kestra OSS prior to versions 1.0.45 and 1.3.21
- Description: Kestra OSS prior to versions 1.0.45 and 1.3.21 contains an authentication bypass vulnerability that allows unauthenticated remote code execution. The flaw exists due to improper URL path validation within the application’s authentication filter.
- Remediation:
- More Info: NVD - CVE-2026-49869
- PoC:
CVE-2026-85696 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: SadTalker
- Description: SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-85696
- PoC:
CVE-2026-85688 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: TEN Framework 0.11.71
- Description: TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-85688
- PoC:
CVE-2026-85672 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: zerox 1.1.20
- Description: zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occurs.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-85672
- PoC:
CVE-2026-75604 NEW
- Severity: 9.0 CRITICAL
- Impacted Products: Next.js
- Description: Next.js applications deployed on a Windows filesystem are affected by a path traversal vulnerability that allows unauthenticated remote code execution. This issue affects applications configured to use both the Pages Router and App Router without Cache Components.
- Remediation:
- More Info: NVD - CVE-2026-75604
- PoC:
CVE-2026-44402 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Voltronic Power SNMP Web Pro 1.1
- Description: Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-44402
- PoC:
CVE-2026-20212 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Cisco NX-OS Software on Cisco Nexus 9000 Series Switches
- Description: Cisco NX-OS Software running on Cisco Nexus 9000 Series Switches with Silicon One ASICs contains a vulnerability in its Silicon One integration that allows an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service. This flaw exists because internal inter-process communication services bind to network interfaces in the default Layer 3 virtual routing and forwarding instance without requiring authentication.
- Remediation:
- More Info: NVD - CVE-2026-20212
- PoC:
CVE-2025-31200
- Severity: 7.5 HIGH
- Impacted Products: tvOS 18.4.1, visionOS 2.4.1, iOS 18.4.1, iPadOS 18.4.1, macOS Sequoia 15.4.1
- Description: A memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
- Remediation:
- More Info: NVD - CVE-2025-31200
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.