
Update: dropped CVE-2026-22191:SSTI-> sandbox escape-> JS exec (No user interaction) CVE-2026-22192+22199: Voltronic UPS preauth root RCE chain Exposed: direct pivot into infra!🔥 Write-up https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/ POC https://github.com/kmkz/Exploits/tree/master/2026 🫡to @catc0n & @VulnCheckAI support!
Post summary
The post announces CVE‑2026‑22191 and CVE‑2026‑22192/22199, provides a PoC and exploit code on GitHub, and details the exploitation chain, but offers no evidence of active exploitation or a patch.

