Weekly Exploit Roundup 2026-09-22
Weekly Exploit Roundup
Generated 2026-09-22T08:00:11.485865+00:00 (UTC)
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Source: The Hacker News | Published: 2026-09-19T08:18:54+00:00 | Score: 25.966A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.
The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.
"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Source: The Hacker News | Published: 2026-09-16T15:50:59+00:00 | Score: 20.548A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Source: The Hacker News | Published: 2026-09-19T09:31:17+00:00 | Score: 20.002SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.
"SolarWinds
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Source: The Hacker News | Published: 2026-09-17T06:39:40+00:00 | Score: 19.989Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.
"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
- Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Source: The Hacker News | Published: 2026-09-22T05:31:59+00:00 | Score: 19.526The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating
- CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
Source: Rapid7 Cybersecurity Blog | Published: 2026-09-15T12:22:50+00:00 | Score: 18.63Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication. An attacker can reportedly trigger the vulnerability by sending a specially crafted email through a vulnerable gateway. CVE-2026-76461 was added to CISA's Known Exploited Vulnerabilities ( KEV )
- CISA Adds One Known Exploited Vulnerability to Catalog
Source: Alerts | Published: 2026-09-21T12:00:00+00:00 | Score: 17.405CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when ag
- Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Source: The Hacker News | Published: 2026-09-18T12:47:04+00:00 | Score: 17.385Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.
The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.
"Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
Source: The Hacker News | Published: 2026-09-16T05:18:06+00:00 | Score: 17.234A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.
The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw.
"JWT authentication
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Source: The Hacker News | Published: 2026-09-16T05:48:28+00:00 | Score: 16.249Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.
"This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said.
The WordPress security company said it has blocked over
End of report.