
#exploit #AppSec 1⃣. CVE-2026-42167: RCE, authentication bypass, and privilege escalation in ProFTPD <=1.3.9 https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc 2⃣. CVE-2026-41940: Critical vulnerability in cPanel & WHM allowing session hijacking and authentication bypass via CRLF injection https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ 3⃣. CVE-2026-40478: Thymeleaf server-side template injection vulnerability https://snyk.io/blog/thymeleaf-injection/ 4⃣. CVE-2026-3854: RCE in GitHub*com/GitHub Enterprise Server https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 5⃣. CVE-2026-20079: Critical Cisco FMC Zero-Day https://github.com/0xBlackash/CVE-2026-20079
Post summary
The post catalogs several 2026 CVEs, providing direct links to working PoC code and detailed technical information, but does not mention active exploitation or patches.








