The 5-Minute Cyber Brief: September 21, 2026

By George Bailey   Published: 09/20/26   Updated: 09/20/26   2 min read

Published: 09/21/26

Monday’s brief is a reboot-and-revoke day: three actively exploited Linux kernel bugs hit their federal KEV due date today, Orkes Conductor’s pre-auth workflow RCE is still being sprayed, SolarWinds Access Rights Manager needs a hard-coded-key emergency upgrade, and CrowdSec’s private-repo theft is a master class in offboarding that stopped too early.

Lead Story

Linux Kernel KEV Trio — Due Today

CISA added exploited flaws in kTLS, ebtables SNAT, and AF_ALG on Friday with a September 21 BOD 26-04 deadline and forensic triage required. Patch the kernel, reboot (or verify live-patch), then ask if the box was dirty first.

Why it matters: Local kernel privilege escalation turns last week’s foothold into this week’s incident. High-throughput Linux estates actually enable these subsystems.

Read more on CyberExperts: Read the analysis

Also Worth Your Attention

Orkes Conductor: Pre-Auth RCE on the Workflow Brain

Unauth INLINE/LAMBDA scripts escape GraalVM and run as the Conductor process. Fortinet is blocking thousands of attempts. Upgrade to 3.30.2+ and find the instances scanners miss.

Why it matters: Orchestrators already hold the keys to everything they orchestrate.

Read more on CyberExperts: Read more

SolarWinds ARM: Hard-Coded Key → Unauth RCE

CVE-2026-28326 affects Access Rights Manager 2026.2 and earlier. Ship 2026.2.1, lock down management paths, rotate integrations if unsure.

Why it matters: The product that maps entitlements is a terrible place to gift remote code execution.

Read more on CyberExperts: Read more

CrowdSec: Departed GitHub Access, 170 Private Repos

TanStack credential theft plus a retained ex-employee GitHub token cloned private source in May. Offboarding that ends at the IdP leaves the code host answering to people who no longer work there.

Why it matters: This is an identity-lifecycle failure every engineering org can copy-paste into their checklist.

Read more on CyberExperts: Read the analysis

Go Deeper

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.