PoC Week 2026-10-11

Posted on Oct 11, 2026

The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.

For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.

CVE-2026-86950

CVE-2026-21589 NEW

CVE-2026-96940 NEW

CVE-2026-102489 NEW

CVE-2026-90970 NEW

  • Severity: 9.9 CRITICAL
  • Impacted Products: GitLab AI Gateway
  • Description: GitLab AI Gateway is affected by a template injection vulnerability that allows an authenticated user to escape the prompt template sandbox. By supplying a specially crafted flow configuration, an attacker can achieve arbitrary command execution on the host hosting the service.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-90970
  • PoC:

CVE-2026-8065 NEW

  • Severity: 9.1 CRITICAL
  • Impacted Products: Hitachi Energy RTU500 end-of-life versions
  • Description: An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
  • Remediation:
  • More Info: NVD - CVE-2026-8065
  • PoC:

CVE-2026-76570 NEW

  • Severity: 9.1 CRITICAL
  • Impacted Products: JCTables 1.21.1
  • Description: Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-76570
  • PoC:

CVE-2026-64849

CVE-2026-42018 NEW

CVE-2026-104286 NEW

CVE-2026-103922 NEW

CVE-2026-103648 NEW

  • Severity: 9.1 CRITICAL
  • Impacted Products: image-downloader 4.3.0
  • Description: Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-103648
  • PoC:

CVE-2026-102427 NEW

  • Severity: 10.0 CRITICAL
  • Impacted Products: OrdaSoft Joomla CCK < 8.3.16
  • Description: Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-102427
  • PoC:

CVE-2026-102425 NEW

  • Severity: 10.0 CRITICAL
  • Impacted Products: Balbooa Forms for Joomla! prior to version 2.4.3.4
  • Description: Balbooa Forms for Joomla! prior to version 2.4.3.4 is vulnerable to code injection that allows for unauthenticated remote code execution. This issue occurs when visitor-supplied form data is interpolated into administrator-defined post-submission scripts without proper sanitization.
  • Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
  • More Info: NVD - CVE-2026-102425
  • PoC:

CVE-2015-3246

CVE-2026-107406 NEW

References

This list was scraped from the quite amazing and highly recommended newsletters below:

Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.