1. Top Action Item

Patch your Linux kernels and your Orkes Conductor instances. CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog this week citing evidence of active exploitation — including CVE-2025-39682 (CVSS 9.8) in the TLS receive path — so any server, appliance, or device still on an older kernel needs updating. Separately, Orkes Conductor's unauthenticated remote code execution flaw (CVE-2026-58138, CVSS 9.8 / 9.3) is being actively exploited in the wild; upgrade to 3.30.2. If you run Cisco Identity Services Engine, apply Cisco's fix for the CVE-2026-76460 authentication bypass (CVSS 10.0), which Dark Reading reports as a zero-day.


2. Exploited This Week

Linux kernel (three flaws, incl. CVE-2025-39682) — CISA KEV

Orkes Conductor — CVE-2026-58138

Cisco Identity Services Engine (ISE) — CVE-2026-76460


3. Critical Patch Roundup

Microsoft Azure AI Foundry — CVE-2026-85889

Microsoft Edge (Chromium-based) — CVE-2026-88097

Microsoft Office for Mac (Outlook and Word) — CVE-2026-78510

Microsoft Azure and Copilot cloud services (September 17 advisories)

SolarWinds Access Rights Manager (ARM) — CVE-2026-28326

WordPress core — "Click2Shell" theme-install chain

Linux kernel — public exploit code for four local-root flaws


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Linux kernel updates (CVE-2025-39682 and two others) — actively exploited, CISA KEV (ubiquitous deployment)
  2. Orkes Conductor 3.30.2 — CVE-2026-58138 (actively exploited, CVSS 9.8 unauthenticated RCE)
  3. Cisco ISE fix — CVE-2026-76460 (CVSS 10.0, reported zero-day authentication bypass)
  4. Microsoft Azure AI Foundry fix plus the September Azure Arc / Container Registry / Dataverse / Azure ML / Logic Apps / Copilot advisories — CVE-2026-85889 (CVSS 10.0) and related (critical, widely deployed cloud services)
  5. Microsoft Edge update — CVE-2026-88097 (widely deployed browser, privilege escalation)
  6. Microsoft Office for Mac update — CVE-2026-78510 (remote code execution in Outlook/Word)
  7. WordPress core update — Click2Shell theme-install chain (widely deployed, patches available now)
  8. SolarWinds Access Rights Manager update — CVE-2026-28326 (CVSS 8.8 pre-auth RCE, ARM 2026.2 and prior)

Sources