PoC Week 2026-10-04
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-88772 NEW
- Severity: 9.0 CRITICAL
- Impacted Products: Citrix NetScaler ADC, Citrix NetScaler Gateway
- Description: Citrix NetScaler ADC and NetScaler Gateway are affected by a memory overflow vulnerability within the Datagram Transport Layer Security (DTLS) packet handling subsystem. When DTLS is enabled, an unauthenticated remote attacker can exploit this flaw to execute arbitrary code or cause a denial of service on the affected appliance.
- Remediation:
- More Info: NVD - CVE-2026-88772
- PoC:
CVE-2026-86950 NEW
- Severity: 8.8 HIGH
- Impacted Products: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, iOS 27
- Description: An out-of-bounds write vulnerability exists in the Apple CoreGraphics framework across iOS, iPadOS, and macOS. The flaw is caused by insufficient bounds checking when parsing graphical data within files.
- Remediation:
- More Info: NVD - CVE-2026-86950
- PoC:
CVE-2026-94127
- Severity: 9.8 CRITICAL
- Impacted Products: F5 BIG-IP Access Policy Manager (APM)
- Description: F5 BIG-IP Access Policy Manager (APM) contains a heap-based buffer overflow vulnerability in its OAuth implementation. When a virtual server is configured with an APM access policy and an OAuth profile acting as an OAuth Authorization Server, an unauthenticated remote attacker can exploit the issue to achieve arbitrary code execution.
- Remediation:
- More Info: NVD - CVE-2026-94127
- PoC:
CVE-2026-93616
- Severity: 9.8 CRITICAL
- Impacted Products: Check Point Security Management Server
- Description: Check Point Security Management Server and associated management components are affected by a path traversal and arbitrary file upload vulnerability. An unauthenticated remote attacker can exploit this flaw to upload arbitrary files and execute code on the management server.
- Remediation:
- More Info: NVD - CVE-2026-93616
- PoC:
CVE-2026-87902
- Severity: 8.1 HIGH
- Impacted Products: WordPress
- Description: WordPress contains a path traversal vulnerability in its page template resolution mechanism that allows an unauthenticated remote attacker to include arbitrary local PHP files. Under specific server and theme configurations, this local file inclusion can be escalated to remote code execution.
- Remediation:
- More Info: NVD - CVE-2026-87902
- PoC:
CVE-2026-85706
- Severity: 10.0 CRITICAL
- Impacted Products: GitLab Community Edition 18.7 before 19.1.8, GitLab Enterprise Edition 18.7 before 19.1.8, GitLab Community Edition 19.2 before 19.2.6, GitLab Enterprise Edition 19.2 before 19.2.6, GitLab Community Edition 19.3 before 19.3.2
- Description: GitLab Community Edition and Enterprise Edition are affected by a path traversal vulnerability in the repository commits API. Under certain conditions, an unauthenticated remote attacker can exploit this issue to read arbitrary files from the underlying host server.
- Remediation:
- More Info: NVD - CVE-2026-85706
- PoC:
CVE-2026-76460
- Severity: 9.8 CRITICAL
- Impacted Products: Cisco Identity Services Engine, Cisco ISE Passive Identity Connector
- Description: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an authentication bypass vulnerability within their API gateway component. An unauthenticated remote attacker can exploit this flaw by sending crafted HTTP or HTTPS requests to an affected API endpoint to bypass access controls on the web-based management interface.
- Remediation:
- More Info: NVD - CVE-2026-76460
- PoC:
CVE-2026-73570
- Severity: 9.8 CRITICAL
- Impacted Products: Zimbra Collaboration (ZCS) versions prior to 10.1.20
- Description: Zimbra Collaboration (ZCS) is affected by an OS command injection vulnerability in its SNMP trap notification handler. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary operating system commands by sending specially crafted SMTP requests.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-73570
- PoC:
CVE-2026-71362
- Severity: 9.1 CRITICAL
- Impacted Products: Adobe Commerce
- Description: Adobe Commerce is affected by an incorrect authorization vulnerability that allows a remote attacker to escalate privileges. An attacker can exploit this issue without requiring user interaction to gain unauthorized access to sensitive resources.
- Remediation:
- More Info: NVD - CVE-2026-71362
- PoC:
CVE-2026-67279 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: MikroTik RouterOS
- Description: MikroTik RouterOS contains an authentication bypass vulnerability in its SSH server implementation due to improper behavioral workflow enforcement. This issue permits an unauthenticated remote attacker to open a session channel and execute commands on the target device.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-67279
- PoC:
CVE-2026-5430 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: WSO2 API Manager, WSO2 API Control Plane, WSO2 Traffic Manager, WSO2 Universal Gateway
- Description: Multiple WSO2 products, including WSO2 API Manager, are affected by an authentication bypass vulnerability caused by improper cryptographic signature verification in the JSON Web Token (JWT) authentication mechanism. A remote, unauthenticated attacker can exploit this flaw to bypass identity verification and gain unauthorized access to the system.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-5430
- PoC:
CVE-2008-4128 NEW
- Severity: 8.1 HIGH
- Impacted Products: Cisco IOS
- Description: Cisco Systems IOS is the underlying operating system of Cisco devices such as switches and routers.A vulnerability exists in HTTP administration in Cisco IOS. The system fails to properly validate the originating source of HTTP administration sessions.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2008-4128
- PoC:
CVE-2026-84388 NEW
- Severity: 9.6 CRITICAL
- Impacted Products: Fortinet FortiPAM Chrome Extension 7.4, Fortinet FortiPAM Chrome Extension 8.0
- Description: Fortinet FortiPAM Chrome Extension is affected by an improper restriction of rendered UI layers or frames vulnerability. A remote, unauthenticated attacker can exploit this flaw to bypass consent mechanisms and disclose sensitive information when a user visits a malicious website.
- Remediation:
- More Info: NVD - CVE-2026-84388
- PoC:
CVE-2026-43786 NEW
- Severity: 7.8 HIGH
- Impacted Products: Apple macOS
- Description: Apple macOS is affected by a local privilege escalation vulnerability resulting from improper handling of insufficient permissions or privileges. A local application can exploit this vulnerability to elevate privileges to root.
- Remediation:
- More Info: NVD - CVE-2026-43786
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.