PoC Week 2026-10-04

Posted on Oct 4, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2026-88772 NEW

CVE-2026-86950 NEW

CVE-2026-94127

CVE-2026-93616

CVE-2026-87902

CVE-2026-85706

CVE-2026-76460

CVE-2026-73570

CVE-2026-71362

CVE-2026-67279 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: MikroTik RouterOS
  • Description: MikroTik RouterOS contains an authentication bypass vulnerability in its SSH server implementation due to improper behavioral workflow enforcement. This issue permits an unauthenticated remote attacker to open a session channel and execute commands on the target device.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-67279
  • PoC:

CVE-2026-5430 NEW

  • Severity: 9.8 CRITICAL
  • Impacted Products: WSO2 API Manager, WSO2 API Control Plane, WSO2 Traffic Manager, WSO2 Universal Gateway
  • Description: Multiple WSO2 products, including WSO2 API Manager, are affected by an authentication bypass vulnerability caused by improper cryptographic signature verification in the JSON Web Token (JWT) authentication mechanism. A remote, unauthenticated attacker can exploit this flaw to bypass identity verification and gain unauthorized access to the system.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-5430
  • PoC:

CVE-2008-4128 NEW

CVE-2026-84388 NEW

  • Severity: 9.6 CRITICAL
  • Impacted Products: Fortinet FortiPAM Chrome Extension 7.4, Fortinet FortiPAM Chrome Extension 8.0
  • Description: Fortinet FortiPAM Chrome Extension is affected by an improper restriction of rendered UI layers or frames vulnerability. A remote, unauthenticated attacker can exploit this flaw to bypass consent mechanisms and disclose sensitive information when a user visits a malicious website.
  • Remediation:
  • More Info: NVD - CVE-2026-84388
  • PoC:

CVE-2026-43786 NEW

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.