TL;DR
Orkes Conductor workflow platform suffers critical pre-auth RCE (CVSS 9.8) being actively exploited in the wild. SolarWinds ARM flaw (CVSS 8.8) has been patched. Three Linux kernel vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog with federal remediation deadline of September 21, 2026.
Executive Summary
- Orkes Conductor Workflow Platform suffers a critical unauthenticated remote code execution vulnerability (CVE-2026-58138, CVSS 9.8/9.3) confirmed being exploited in active attacks.
- SolarWinds Access Rights Manager patched a high-severity hard-coded cryptographic key flaw (CVE-2026-28326, CVSS 8.8) enabling unauthenticated RCE.
- Three Linux kernel vulnerabilities—including race conditions and out-of-bounds write flaws—were added to CISA's Known Exploited Vulnerabilities catalog with federal remediation deadline of September 21, 2026.
- Gyazo image-sharing platform confirmed breach of 23.6 million user records via exploited server vulnerability.
- North Korean WaterPlum hacking group infected at least 30,000 devices worldwide from December 2025 through July 2026, stealing over $10.7 million in cryptocurrency. ⚠
Top Threats Today
1. Orkes Conductor Pre-Auth RCE Actively Exploited
Severity: CRITICAL Affected: Technology
A critical vulnerability in Orkes Conductor is being actively exploited in the wild, according to Fortinet. [1] CVE-2026-58138 relates to unauthenticated remote code execution and carries a CVSS v3.1 score of 9.8 and CVSS v4 score of 9.3. [1] Orkes Conductor versions 3.21.21 and earlier are affected. ⚠
Sources:[1] The Hacker News
Recommended Action
- Immediately identify all Orkes Conductor deployments in your environment
- Apply security updates to Orkes Conductor 3.21.22 or later as soon as available
- Monitor network traffic for exploitation attempts targeting Orkes Conductor instances
- Implement network segmentation to restrict access to Conductor API endpoints
2. SolarWinds ARM Hard-Coded Key RCE Patched
Severity: HIGH Affected: Technology
SolarWinds has released security updates to address CVE-2026-28326, a high-severity flaw in Access Rights Manager (ARM) that enables unauthenticated remote code execution via a hard-coded cryptographic key. [1] The vulnerability is rated CVSS 8.8 out of 10.0. [1]
Sources:[1] The Hacker News
Recommended Action
- Apply SolarWinds ARM security patches without delay
- Review access logs for unauthorized API access or code execution attempts
- Rotate any credentials that may have been exposed through hard-coded key compromise
- Audit network access to SolarWinds ARM instances and restrict to trusted sources
3. Linux Kernel Race Condition and Out-of-Bounds Write Flaws in CISA KEV
Severity: HIGH Affected: Technology
Three Linux kernel vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog with a federal remediation deadline of September 21, 2026. [1][2][3] CVE-2025-39964 is a race condition vulnerability in AF_ALG sockets that allows concurrent writes to cause data interleaving and socket state inconsistencies. [1] CVE-2026-53266 is an out-of-bounds write vulnerability in the ebtables SNAT target allowing ARP sender hardware address rewrite to write directly into nonlinear socket-buffer fragments. [2] CVE-2025-39682 is an improper check for unusual conditions in the TLS receive path allowing zero-length records to bypass intended recvmsg() record-type handling. [3] CISA notes that impacted products could be end-of-life or end-of-service, and users are advised to discontinue use and transition to supported versions. [2][3]
Sources:[1] CISA KEV[2] CISA KEV[3] CISA KEV
Recommended Action
- Prioritize patching of Linux kernel systems to current supported versions by September 21, 2026
- Identify systems running end-of-life or end-of-service Linux versions and plan immediate migration
- Monitor affected systems for exploitation attempts targeting AF_ALG sockets and ebtables functionality
- Apply kernel security updates through your distribution's package manager
4. Gyazo Data Breach Exposes 23.6 Million User Records
Severity: HIGH Affected: Technology
Gyazo, an image-sharing platform, confirmed a data breach after hackers exploited a vulnerability in its image upload server, stealing 23.6 million user records. [1]
Sources:[1] BleepingComputer
Recommended Action
- Change Gyazo account passwords immediately if you maintain an active account
- Monitor accounts for unauthorized access or credential misuse
- Review any sensitive images that may have been uploaded to Gyazo for exposure
- Enable multi-factor authentication on any associated email accounts
Ongoing Coverage
Previous briefings covered Microsoft's 974-patch Patch Tuesday release, Cisco ISE authentication bypass (CVE-2026-76460), and WordPress plugin vulnerabilities. No additional material updates to those stories appeared in today's sources. For prior coverage, see earlier briefings on related topics.
Additional Intelligence
North Korean WaterPlum Campaign: A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026, transferring over $10.7 million in stolen cryptocurrency to North Korea. [7]
ShinyHunters Breach of Cl0p Leak Site: The ShinyHunters extortion gang reportedly breached the Clop (aka Cl0p) ransomware operation's data leak site on Tor, defacing the site and allegedly stealing server data and private keys for its onion service. [8]
Today’s Action Checklist
- ☐ URGENT: Audit Orkes Conductor deployments and apply patches immediately
- ☐ URGENT: Deploy SolarWinds ARM patches and review access logs for compromise
- ☐ URGENT: Identify Linux systems running vulnerable kernel versions; plan patching by September 21, 2026
- ☐ Notify users with Gyazo accounts to change passwords and enable MFA
- ☐ Review CISA KEV catalog for any other CVEs affecting your environment