PoC Week 2026-09-21
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-21962
- Severity: 10.0 CRITICAL
- Impacted Products: Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware 12.2.1.4.0, Oracle Fusion Middleware 14.1.1.0.0, Oracle Fusion Middleware 14.1.2.0.0
- Description: Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in are affected by an improper access control vulnerability that allows an unauthenticated remote attacker to compromise the server. This flaw enables unauthorized access to data and the potential execution of arbitrary commands via the network.
- Remediation:
- More Info: NVD - CVE-2026-21962
- PoC:
CVE-2026-76461 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Cisco Secure Email Gateway, Cisco AsyncOS Software
- Description: Cisco Secure Email Gateway running Cisco AsyncOS Software contains a SQL injection vulnerability in its email parsing logic that allows an unauthenticated, remote attacker to execute arbitrary commands. The issue stems from improper neutralization of user-supplied data in processed email messages.
- Remediation:
- More Info: NVD - CVE-2026-76461
- PoC:
CVE-2026-87491 NEW
- Severity: 8.8 HIGH
- Impacted Products: Google Chrome prior to version 153.0.8010.36, Google Chrome prior to version 153.0.8010.35, Chromium-based web browsers
- Description: Google Chrome and other Chromium-based web browsers contain an out-of-bounds memory write vulnerability in the V8 JavaScript and WebAssembly engine. An unauthenticated remote attacker can exploit this flaw by enticing a user to view a specially crafted HTML page.
- Remediation:
- More Info: NVD - CVE-2026-87491
- PoC:
CVE-2026-85046
- Severity: 8.8 HIGH
- Impacted Products: Google Chrome prior to version 152.0.7977.82
- Description: Google Chrome is affected by a type confusion vulnerability within its V8 JavaScript and WebAssembly engine prior to version 152.0.7977.82. An unauthenticated remote attacker can exploit this flaw by convincing a user to view a specially crafted HTML page.
- Remediation:
- More Info: NVD - CVE-2026-85046
- PoC:
CVE-2026-86218
- Severity: 10.0 CRITICAL
- Impacted Products: N-able N-central
- Description: N-able N-central is affected by a static code injection vulnerability that allows an unauthenticated remote attacker to achieve arbitrary code execution on the server.
- Remediation:
- More Info: NVD - CVE-2026-86218
- PoC:
CVE-2026-86060 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: MikroTik RouterOS 6.49.21, MikroTik RouterOS 7.23.4, MikroTik RouterOS 7.24.2
- Description: MikroTik RouterOS is affected by an argument injection vulnerability in its SSH login path that allows remote attackers to escalate privileges. By supplying a specially crafted username, an attacker can manipulate internal session policy masks to gain full administrative access to the system.
- Remediation:
- More Info: NVD - CVE-2026-86060
- PoC:
CVE-2026-85706 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: GitLab Community Edition 18.7 before 19.1.8, GitLab Enterprise Edition 18.7 before 19.1.8, GitLab Community Edition 19.2 before 19.2.6, GitLab Enterprise Edition 19.2 before 19.2.6, GitLab Community Edition 19.3 before 19.3.2
- Description: GitLab Community Edition and Enterprise Edition are affected by a path traversal vulnerability in the repository commits API. Under certain conditions, an unauthenticated remote attacker can exploit this issue to read arbitrary files from the underlying host server.
- Remediation:
- More Info: NVD - CVE-2026-85706
- PoC:
CVE-2026-82078
- Severity: 9.8 CRITICAL
- Impacted Products: PaperCut MF, PaperCut NG
- Description: PaperCut MF and PaperCut NG are affected by an unsafe dynamic class loading vulnerability in their database connector utilities. An attacker with the ability to modify application configuration settings can leverage this flaw to execute arbitrary code on the underlying server.
- Remediation:
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut
- Add exploit module for the recent PaperCut MF/NG 0day (CVE-2026-81578 + CVE-2026-82078) by sfewer-r7 · Pull Request #21842 · rapid7/metasploit-framework · GitHub
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078
- More Info: NVD - CVE-2026-82078
- PoC:
CVE-2026-81578
- Severity: 8.6 HIGH
- Impacted Products: PaperCut MF, PaperCut NG
- Description: PaperCut MF and PaperCut NG are affected by an authentication bypass vulnerability in their web management interface. An unauthenticated remote attacker can exploit this flaw to execute privileged administrative actions and alter system configurations without authenticating.
- Remediation:
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut
- Add exploit module for the recent PaperCut MF/NG 0day (CVE-2026-81578 + CVE-2026-82078) by sfewer-r7 · Pull Request #21842 · rapid7/metasploit-framework · GitHub
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578
- More Info: NVD - CVE-2026-81578
- PoC:
CVE-2026-65400
- Severity: 9.8 CRITICAL
- Impacted Products: Apple macOS
- Description: Apple macOS contains an authentication bypass vulnerability in its Screen Sharing component that allows a network-based attacker to authenticate without providing valid credentials. This issue is caused by improper state management during the authentication protocol.
- Remediation:
- More Info: NVD - CVE-2026-65400
- PoC:
CVE-2026-19490 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Citrix NetScaler ADC, Citrix NetScaler Gateway
- Description: Citrix NetScaler ADC and NetScaler Gateway contain an authentication bypass vulnerability that allows an unauthenticated remote attacker to gain unauthorized access to protected resources. The issue affects appliances configured as a Gateway or as an AAA virtual server under specific configurations.
- Remediation:
- More Info: NVD - CVE-2026-19490
- PoC:
CVE-2026-82329
- Severity: 10.0 CRITICAL
- Impacted Products: JFrog Artifactory
- Description: JFrog Artifactory contains an improper authentication vulnerability that allows unauthenticated remote attackers to bypass security controls. Under default configurations, an attacker with network access to the web interface or API can obtain full administrative privileges.
- Remediation:
- More Info: NVD - CVE-2026-82329
- PoC:
CVE-2026-76460 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Cisco Identity Services Engine, Cisco ISE Passive Identity Connector
- Description: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an authentication bypass vulnerability within their API gateway component. An unauthenticated remote attacker can exploit this flaw by sending crafted HTTP or HTTPS requests to an affected API endpoint to bypass access controls on the web-based management interface.
- Remediation:
- More Info: NVD - CVE-2026-76460
- PoC:
CVE-2026-39987 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: marimo versions prior to 0.23.0
- Description: marimo is affected by a pre-authentication remote code execution vulnerability in its terminal WebSocket endpoint. An unauthenticated attacker can exploit this flaw to obtain a full interactive shell and execute arbitrary system commands.
- Remediation:
- Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass · GHSA-2679-6mx9-h9xc · GitHub Advisory Database · GitHub
- https://github.com/marimo-team/marimo/commit/c24d4806398f30be6b12acd6c60d1d7c68cfd12a
- fix: properly authenticate terminal route by mscolnick · Pull Request #9098 · marimo-team/marimo · GitHub
- More Info: NVD - CVE-2026-39987
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.