Thursday, October 8, 2026

PoC

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that can expose active users' session cookies and enable remote code execution (RCE) as the...

PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on Windows Server

A proof-of-concept has been published that bypasses Microsoft’s mitigation for the NTLM reflection vulnerability tracked as CVE-2025-33073 and allows escalation to NT AUTHORITYSYSTEM on...

PoC Released for Microsoft Exchange Server EWS InstallApp SSRF Vulnerability

A proof-of-concept exploit has been released for CVE-2026-45502, a server-side request forgery (SSRF) vulnerability in the Microsoft Exchange Server's Exchange Web Services (EWS) InstallApp...

Critical Wazuh Flaw Enables Threat Actors to Alter Alerts and Remove Logs

A critical security flaw in Wazuh Manager could allow unauthenticated threat actors to tamper with alerts, delete forensic evidence, and execute arbitrary OpenSearch operations...

PoC Exploit Released for Linux Kernel Guest-to-Host Escape Vulnerability

A proof-of-concept (PoC) exploit has been publicly released for a critical Linux kernel vulnerability, tracked as CVE-2026-46316, enabling guest-to-host escape in KVM/arm64 environments. The...

Ivanti Command Injection Flaw Exploited After PoC Code Release

Ivanti Sentry is facing active exploitation attempts following the public release of proof-of-concept (PoC) code targeting a critical OS command injection vulnerability tracked as...

PoC Exploit Released for Cisco Unified Communications Manager Security Vulnerability

A proof-of-concept (PoC) exploit has been released for a critical server-side request forgery (SSRF) vulnerability impacting Cisco Unified Communications Manager (Unified CM) and Unified...

PoC Exploit Released for DirtyDecrypt Linux Kernel Vulnerability

PoC exploit code for the DirtyDecrypt (DirtyCBC) Linux kernel vulnerability has been released publicly, turning a previously theoretical local privilege escalation into a practical,...

20-Year-Old PostgreSQL Flaw Gets Public PoC Exploit for Remote Code Execution

A newly released proof-of-concept (PoC) exploit for CVE-2026-2005 has brought renewed attention to a critical vulnerability in PostgreSQL’s pgcrypto extension, exposing systems to remote...

Mythos Preview Automates PoC Exploit Creation for Vulnerability Research

A new AI model from Anthropic is changing how security teams find and prove software vulnerabilities. It is raising hard questions about what happens...

PoC Released for 18-Year-Old NGINX Flaw Allowing Remote Code Execution

A critical vulnerability in NGINX's source code, hidden since 2008, has finally been exposed, and a working exploit is already in the wild. Security researchers...