Published: 09/21/26
Monday’s brief is a reboot-and-revoke day: three actively exploited Linux kernel bugs hit their federal KEV due date today, Orkes Conductor’s pre-auth workflow RCE is still being sprayed, SolarWinds Access Rights Manager needs a hard-coded-key emergency upgrade, and CrowdSec’s private-repo theft is a master class in offboarding that stopped too early.
Lead Story
Linux Kernel KEV Trio — Due Today
CISA added exploited flaws in kTLS, ebtables SNAT, and AF_ALG on Friday with a September 21 BOD 26-04 deadline and forensic triage required. Patch the kernel, reboot (or verify live-patch), then ask if the box was dirty first.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Local kernel privilege escalation turns last week’s foothold into this week’s incident. High-throughput Linux estates actually enable these subsystems.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
Orkes Conductor: Pre-Auth RCE on the Workflow Brain
Unauth INLINE/LAMBDA scripts escape GraalVM and run as the Conductor process. Fortinet is blocking thousands of attempts. Upgrade to 3.30.2+ and find the instances scanners miss.
Why it matters: Orchestrators already hold the keys to everything they orchestrate.
Read more on CyberExperts: Read more
SolarWinds ARM: Hard-Coded Key → Unauth RCE
CVE-2026-28326 affects Access Rights Manager 2026.2 and earlier. Ship 2026.2.1, lock down management paths, rotate integrations if unsure.
Why it matters: The product that maps entitlements is a terrible place to gift remote code execution.
Read more on CyberExperts: Read more
CrowdSec: Departed GitHub Access, 170 Private Repos
TanStack credential theft plus a retained ex-employee GitHub token cloned private source in May. Offboarding that ends at the IdP leaves the code host answering to people who no longer work there.
Why it matters: This is an identity-lifecycle failure every engineering org can copy-paste into their checklist.
Read more on CyberExperts: Read the analysis
Go Deeper
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.