🛡️ Cybersecurity Vulnerability Watch
Patch your Linux kernels and your Orkes Conductor instances. CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog this week citing evidence of active exploitation…
🛡️ Cybersecurity Vulnerability Watch
Week of: 2026-09-13 to 2026-09-19 Reporting window: Most recently completed Sunday–Saturday (excludes the in-progress week).
1. Top Action Item
Patch your Linux kernels and your Orkes Conductor instances. CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog this week citing evidence of active exploitation — including CVE-2025-39682 (CVSS 9.8) in the TLS receive path — so any server, appliance, or device still on an older kernel needs updating. Separately, Orkes Conductor's unauthenticated remote code execution flaw (CVE-2026-58138, CVSS 9.8 / 9.3) is being actively exploited in the wild; upgrade to 3.30.2. If you run Cisco Identity Services Engine, apply Cisco's fix for the CVE-2026-76460 authentication bypass (CVSS 10.0), which Dark Reading reports as a zero-day.
2. Exploited This Week
Linux kernel (three flaws, incl. CVE-2025-39682) — CISA KEV
- Source: The Hacker News
- Link: The Hacker News
- Severity: CVE-2025-39682 rated CVSS 9.8; the other two, see source
- What's happening: CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog on Friday, citing evidence of active exploitation; the named flaw, CVE-2025-39682, is an improper check for unusual or exceptional conditions in the TLS receive path.
- Fix: Apply your distribution's or vendor's kernel update; consult the CISA KEV entry for the remediation timeline.
Orkes Conductor — CVE-2026-58138
- Source: The Hacker News (citing Fortinet)
- Link: The Hacker News
- Severity: Critical (CVSS v3.1 9.8 / CVSS v4 9.3)
- What's happening: Fortinet reports that this unauthenticated remote code execution flaw is being actively exploited in the wild; Orkes Conductor 3.21.21 before 3.30.2 is affected.
- Fix: Upgrade to Orkes Conductor 3.30.2.
Cisco Identity Services Engine (ISE) — CVE-2026-76460
- Source: Dark Reading
- Link: Dark Reading
- Severity: Critical (CVSS 10.0)
- What's happening: Dark Reading reports a zero-day authentication bypass affecting Cisco ISE's API endpoint authentication, rated a maximum 10 out of 10.
- Fix: see source — the provided article does not name a fixed version; follow Cisco's advisory guidance for ISE.
3. Critical Patch Roundup
Microsoft Azure AI Foundry — CVE-2026-85889
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 10.0)
- What's happening: Missing authentication for a critical function allows an unauthorized attacker to elevate privileges over a network.
- Fix: Microsoft has released fixes; the article states no customer action is required.
Microsoft Edge (Chromium-based) — CVE-2026-88097
- Source: Microsoft MSRC
- Link: Microsoft MSRC
- Severity: see source
- What's happening: A use-after-free in Edge allows an unauthorized attacker to elevate privileges locally.
- Fix: Apply the Edge security update in the MSRC advisory.
Microsoft Office for Mac (Outlook and Word) — CVE-2026-78510
- Source: Microsoft MSRC
- Link: Microsoft MSRC
- Severity: see source (remote code execution)
- What's happening: Microsoft is shipping security updates for Office for Mac to fix a remote code execution vulnerability; customers running other Office software do not need to act.
- Fix: Install the Office for Mac update via the advisory's release notes.
Microsoft Azure and Copilot cloud services (September 17 advisories)
- Source: Microsoft MSRC
- Link: Azure Arc — CVE-2026-70009 · Container Registry — CVE-2026-69865 · Dataverse — CVE-2026-77903 · Azure Machine Learning — CVE-2026-68791 · Azure Logic Apps — CVE-2026-83944 · Copilot — CVE-2026-55946 · M365 Copilot — CVE-2026-85885 · M365 Copilot Business Chat — CVE-2026-78501
- Severity: see source (Microsoft advisories; no CVSS in the provided snippets)
- What's happening: Microsoft published fixes for path traversal, authorization/authentication bypass, and command-injection issues that let attackers escalate privileges or disclose information over a network across Azure Arc, Container Registry, Dataverse, Azure Machine Learning, Azure Logic Apps, and Copilot services.
- Fix: Apply the updates in the linked advisories for each affected service or component.
SolarWinds Access Rights Manager (ARM) — CVE-2026-28326
- Source: The Hacker News
- Link: The Hacker News
- Severity: High (CVSS 8.8)
- What's happening: A hard-coded key flaw in ARM could lead to unauthenticated remote code execution; all versions of Access Rights Manager 2026.2 and prior are affected.
- Fix: Apply SolarWinds' security updates for ARM.
WordPress core — "Click2Shell" theme-install chain
- Source: The Hacker News
- Link: The Hacker News
- Severity: see source
- What's happening: A crafted web link opened by a logged-in administrator can install a theme from the official WordPress.org directory without anyone clicking Install; reporter pwn.ai says the chain can lead to code execution.
- Fix: Apply the WordPress core patches released this week.
Linux kernel — public exploit code for four local-root flaws
- Source: The Hacker News
- Link: The Hacker News
- Severity: see source
- What's happening: A researcher released working exploit code for four kernel flaws that each let a local user gain root; kernel maintainers fixed all four over the past few weeks, so only hosts on older kernels are affected.
- Fix: Update any machine still running an older kernel to an up-to-date kernel.
4. Home / SOHO Impact
- Windows and Edge users: Install Microsoft's September updates, and make sure Edge picks up the CVE-2026-88097 privilege-escalation fix.
- Mac users: Install the Microsoft Office for Mac update (CVE-2026-78510 affects Outlook and Word). Separately, Unit 42 reports macOS AMOS infostealer campaigns using fake setup guides to steal credentials — don't run installers from unsolicited "how to install" pages.
- Home Linux devices — Raspberry Pi, NAS boxes, home servers: Run your distribution's kernel update; three kernel flaws are on CISA's actively exploited list this week.
- Anyone running a WordPress site: Update WordPress core now — a malicious link opened while logged in as admin can silently install a theme (Click2Shell).
- Small offices running SolarWinds Access Rights Manager: Apply SolarWinds' update; the flaw is an unauthenticated remote code execution issue (CVSS 8.8) in ARM 2026.2 and prior.
- Small IT shops using Cisco ISE: Ask your Cisco partner about the CVE-2026-76460 fix and limit who can reach ISE's management and API interfaces.
5. Enterprise Impact
- Cisco ISE (CVE-2026-76460, CVSS 10.0, reported as a zero-day): Inventory ISE deployments, review exposure of ISE API endpoints, restrict management access, and apply Cisco's fix or mitigation as soon as it is available; watch authentication logs for bypass patterns.
- Orkes Conductor (CVE-2026-58138): Upgrade to 3.30.2 immediately and hunt for post-exploitation activity on any internet-facing instance — the flaw is an unauthenticated RCE being actively exploited.
- Linux kernel (CISA KEV + public local-root exploits): Prioritize kernel updates across server and appliance fleets, starting with internet-facing systems; where unprivileged local access is broadly granted, treat the public exploit code as a reason to accelerate patching.
- Microsoft (September wave): Apply the Azure Arc, Container Registry, Dataverse, Azure Machine Learning, Azure Logic Apps, and Copilot fixes; Azure AI Foundry (CVE-2026-85889, CVSS 10.0) requires no customer action per Microsoft. Dark Reading notes Microsoft issued emergency fixes after a Patch Tuesday wave of nearly 1,000 CVEs — validate that your deployed patches actually took.
- SolarWinds ARM (CVE-2026-28326): Patch ARM 2026.2 and prior; because it is pre-authentication RCE, review ARM hosts for signs of compromise.
- WordPress hosting: If you host WordPress for others, force core updates and monitor for unexpected theme installations, especially following admin link clicks.
- AI agent platforms: Unit 42 found that default AWS AgentCore Harness configurations let prompt injection exfiltrate credentials — review agent permissions and secret handling before expanding agent deployments.
- Supply chain and offboarding hygiene: CrowdSec disclosed that roughly 170 private GitHub repositories were copied using a departed employee's still-active GitHub account, whose laptop was compromised in May's TanStack npm supply chain attack — audit offboarding, revoke stale access, rotate credentials, and review dependency integrity in CI/CD.
6. What To Patch First
- Linux kernel updates (CVE-2025-39682 and two others) — actively exploited, CISA KEV (ubiquitous deployment)
- Orkes Conductor 3.30.2 — CVE-2026-58138 (actively exploited, CVSS 9.8 unauthenticated RCE)
- Cisco ISE fix — CVE-2026-76460 (CVSS 10.0, reported zero-day authentication bypass)
- Microsoft Azure AI Foundry fix plus the September Azure Arc / Container Registry / Dataverse / Azure ML / Logic Apps / Copilot advisories — CVE-2026-85889 (CVSS 10.0) and related (critical, widely deployed cloud services)
- Microsoft Edge update — CVE-2026-88097 (widely deployed browser, privilege escalation)
- Microsoft Office for Mac update — CVE-2026-78510 (remote code execution in Outlook/Word)
- WordPress core update — Click2Shell theme-install chain (widely deployed, patches available now)
- SolarWinds Access Rights Manager update — CVE-2026-28326 (CVSS 8.8 pre-auth RCE, ARM 2026.2 and prior)
Sources
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild — https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
- Cisco Zero-Day Highlights API Endpoint Authentication Issues — https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
- Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation — https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE — https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root — https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html
- CVE-2026-88097 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-88097
- CVE-2026-78510 Microsoft Outlook and Word Remote Code Execution Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78510
- CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55946
- CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85885
- CVE-2026-78501 Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78501
- CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70009
- CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69865
- CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77903
- CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68791
- CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83944
- Microsoft Issues Emergency Fixes After Massive Patch Tuesday — https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday
- A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity — https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/
- Atomic macOS (AMOS) Stealer Activity — https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/
- CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories — https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
More from News