PoC Week 2026-09-27

Posted on Sep 27, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2026-21962

CVE-2026-87491

CVE-2026-85046

CVE-2026-87902 NEW

CVE-2026-76461

CVE-2026-76460

CVE-2026-94127 NEW

CVE-2026-93616 NEW

CVE-2026-89026 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Issabel PBX software, before commit b97dbaf
  • Description: The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was …
  • Remediation:
  • More Info: NVD - CVE-2026-89026
  • PoC:

CVE-2026-83549

  • Severity: 7.2 HIGH
  • Impacted Products: SonicWall Secure Mobile Access (SMA) 1000 Series
  • Description: SonicWall Secure Mobile Access (SMA) 1000 Series appliances contain an OS command injection vulnerability in the Appliance Management Console (AMC). An authenticated remote administrator can exploit this vulnerability to execute arbitrary operating system commands on the device.
  • Remediation:
  • More Info: NVD - CVE-2026-83549
  • PoC:

CVE-2026-65400

CVE-2026-57148 NEW

CVE-2026-57147 NEW

CVE-2026-57141 NEW

CVE-2026-57139 NEW

CVE-2026-53710 NEW

  • Severity: 10.0 CRITICAL
  • Impacted Products: MCP Context Forge, python_sandbox_server < 1.0.2
  • Description: MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal dangerous dunder strings. An attacker can construct dunder names at runtime, traverse the Python class hierarchy, reach subprocess.Popen, and…
  • Remediation:
  • More Info: NVD - CVE-2026-53710
  • PoC:

CVE-2026-12793 NEW

CVE-2024-58385 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Yonyou U8 CRM
  • Description: Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write backdoor files and execute arbitrary operating system commands. Exploitation evidence was first …
  • Remediation:
  • More Info: NVD - CVE-2024-58385
  • PoC:

CVE-2023-54398 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: Yonyou U8 Cloud
  • Description: Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can exploit the doAction method, which passes raw HTTP request body data directly to ObjectInputStream.readObject() without filtering, to achieve remote code execution. Exploitation evidence was first observed by the Shado…
  • Remediation:
  • More Info: NVD - CVE-2023-54398
  • PoC:

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.