PoC Week 2026-10-11
The most featured CVEs in this week’s security newsletters, with public Proof-of-Concepts, ordered by mention count.
For the most up-to-date and accurate info, visit the NIST links. Always audit PoCs thoroughly before running them. I don’t vouch for any links in this list: follow them with caution.
CVE-2026-86950
- Severity: 8.8 HIGH
- Impacted Products: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, iOS 27
- Description: An out-of-bounds write vulnerability exists in the Apple CoreGraphics framework across iOS, iPadOS, and macOS. The flaw is caused by insufficient bounds checking when parsing graphical data within files.
- Remediation:
- More Info: NVD - CVE-2026-86950
- PoC:
CVE-2026-21589 NEW
- Severity: Unknown
- Impacted Products: Bamboo Data Center, Bitbucket Data Center, Confluence Data Center, Crowd Data Center, Jira Service Management Data Center
- Description: Multiple Atlassian products, including Bamboo Data Center, Bitbucket Data Center, Confluence Data Center, Crowd Data Center, Jira Service Management Data Center, Jira Software Data Center, Crucible, and Fisheye, are affected by a path traversal vulnerability that permits arbitrary file access. An unauthenticated remote attacker can exploit this flaw to read specific files located within the web application root directory.
- Remediation:
- CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products | Atlassian Support | Atlassian Documentation
- [BAM-26567] Arbitrary File Access in Bamboo Data Center - Create and track feature requests for Atlassian products.
- [BSERV-20604] Arbitrary File Access in Bitbucket Data Center - Create and track feature requests for Atlassian products.
- More Info: NVD - CVE-2026-21589
- PoC:
CVE-2026-96940 NEW
- Severity: 8.8 HIGH
- Impacted Products: Microsoft Exchange Server
- Description: Microsoft Exchange Server contains an elevation of privilege vulnerability caused by weak authorization enforcement. An authenticated attacker can exploit this flaw over a network to access and read unauthorized mailbox data across the organization.
- Remediation:
- More Info: NVD - CVE-2026-96940
- PoC:
CVE-2026-102489 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Zammad 6.3.0 through 6.5.4, Zammad 7.0.0 and later
- Description: Zammad contains a session information disclosure and hijacking vulnerability in the standalone WebSocket server that allows an unauthenticated remote attacker to obtain active session identifiers and execute arbitrary code. The flaw is present in default installations of Zammad 6.3.0 through 6.5.4.
- Remediation:
- More Info: NVD - CVE-2026-102489
- PoC:
CVE-2026-90970 NEW
- Severity: 9.9 CRITICAL
- Impacted Products: GitLab AI Gateway
- Description: GitLab AI Gateway is affected by a template injection vulnerability that allows an authenticated user to escape the prompt template sandbox. By supplying a specially crafted flow configuration, an attacker can achieve arbitrary command execution on the host hosting the service.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-90970
- PoC:
CVE-2026-8065 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: Hitachi Energy RTU500 end-of-life versions
- Description: An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
- Remediation:
- More Info: NVD - CVE-2026-8065
- PoC:
CVE-2026-76570 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: JCTables 1.21.1
- Description: Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-76570
- PoC:
CVE-2026-64849
- Severity: Unknown
- Impacted Products: MLflow, prior to version 3.15.0
- Description: MLflow prior to version 3.15.0 is vulnerable to server-side request forgery (SSRF) in its webhook delivery mechanism. An unauthenticated attacker can exploit this flaw to bypass URL validation and perform unauthorized HTTP requests to internal services and cloud metadata endpoints.
- Remediation:
- More Info: NVD - CVE-2026-64849
- PoC:
CVE-2026-42018 NEW
- Severity: 7.5 HIGH
- Impacted Products: JFrog Artifactory prior to version 7.146.8
- Description: JFrog Artifactory is affected by an improper authentication vulnerability where internal anonymous-user tokens may be returned to unauthenticated callers even when anonymous access is disabled. This flaw can allow remote attackers to gain unauthorized access to sensitive resources.
- Remediation:
- More Info: NVD - CVE-2026-42018
- PoC:
CVE-2026-104286 NEW
- Severity: 9.8 CRITICAL
- Impacted Products: Fortinet FortiMail
- Description: Fortinet FortiMail contains an improper limitation of a pathname to a restricted directory (path traversal) and null byte injection vulnerability in the webmail Identity-Based Encryption (IBE) service.
- Remediation:
- More Info: NVD - CVE-2026-104286
- PoC:
CVE-2026-103922 NEW
- Severity: 9.3 CRITICAL
- Impacted Products: Ionic Capacitor
- Description: Ionic Capacitor is affected by an origin validation error vulnerability within its Android and iOS WebView navigation guard. This flaw allows attacker-controlled remote content to be executed under the context of the application’s trusted origin when a user navigates to an untrusted link.
- Remediation:
- More Info: NVD - CVE-2026-103922
- PoC:
CVE-2026-103648 NEW
- Severity: 9.1 CRITICAL
- Impacted Products: image-downloader 4.3.0
- Description: Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-103648
- PoC:
CVE-2026-102427 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: OrdaSoft Joomla CCK < 8.3.16
- Description: Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-102427
- PoC:
CVE-2026-102425 NEW
- Severity: 10.0 CRITICAL
- Impacted Products: Balbooa Forms for Joomla! prior to version 2.4.3.4
- Description: Balbooa Forms for Joomla! prior to version 2.4.3.4 is vulnerable to code injection that allows for unauthenticated remote code execution. This issue occurs when visitor-supplied form data is interpolated into administrator-defined post-submission scripts without proper sanitization.
- Remediation: Follow vendor security advisories and apply the latest patches. Review affected systems and prioritize patching based on exploitability and business impact.
- More Info: NVD - CVE-2026-102425
- PoC:
CVE-2015-3246
- Severity: 5.1 MEDIUM
- Impacted Products: libuser before 0.56.13-8, libuser 0.60 before 0.60-7, usermode package
- Description: libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
- Remediation:
- More Info: NVD - CVE-2015-3246
- PoC:
CVE-2026-107406 NEW
- Severity: Unknown
- Impacted Products: Citrix NetScaler ADC, Citrix NetScaler Gateway
- Description: Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability in their SAML processing components. When configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP), an attacker can exploit this condition to execute arbitrary code or trigger a denial of service.
- Remediation:
- More Info: NVD - CVE-2026-107406
- PoC:
References
This list was scraped from the quite amazing and highly recommended newsletters below:
Thanks for reading! For corrections, omissions (e.g. newsletter recs) feel free to get in touch.