September 20, 2026 is shaping up to be one of those days where the threat board lights up across every layer of the stack — from enterprise access management tools and workflow orchestration platforms to the Linux kernel itself, and even the software supply chain. The common thread running through today's incidents is a dangerous combination of unauthenticated access, unpatched systems, and trusted tooling turned against defenders. Here is what your team needs to know right now.

SolarWinds Access Rights Manager is once again in the spotlight. CVE-2026-28326, rated 8.8 on the CVSS scale, involves a hard-coded cryptographic key embedded in the ARM product. Hard-coded keys are a particularly insidious class of vulnerability because they cannot be rotated by the customer — the fix must come from the vendor. In this case, an unauthenticated attacker who knows the key can achieve remote code execution without presenting any credentials. Given SolarWinds' history as a high-value target and the privileged nature of Access Rights Manager — which sits at the heart of identity and permission workflows — this vulnerability should be treated as critical regardless of its 8.8 score. Patch immediately and verify that no ARM instances are exposed to untrusted networks.

Equally urgent is CVE-2026-58138 in Orkes Conductor, a popular open-source and enterprise workflow orchestration platform. This vulnerability carries a CVSS v3.1 score of 9.8 and is already being actively exploited in the wild according to Fortinet's threat intelligence. Pre-authentication RCE at this severity level in a workflow engine is particularly dangerous because Conductor instances often have deep integrations with internal APIs, databases, and cloud services. A successful exploit does not just compromise one server — it potentially hands an attacker the keys to every downstream system that Conductor touches. If your organization runs Orkes Conductor in any environment, treat this as an emergency. Isolate exposed instances, apply vendor patches, and audit workflow integrations for signs of lateral movement or unauthorized API calls.

On the Linux kernel front, CISA has added three vulnerabilities to its Known Exploited Vulnerabilities catalog in rapid succession, a signal that active exploitation is confirmed and widespread. CVE-2025-39682, rated 9.8, affects the TLS receive path and involves improper handling of unusual or exceptional conditions — a class of bug that can be triggered remotely in network-facing workloads. CVE-2025-39964 is a race condition vulnerability, and CVE-2026-53266 is an out-of-bounds write. All three are now on the KEV list, meaning federal agencies have binding remediation deadlines, but every organization running Linux — which is to say, nearly every organization — should treat these with the same urgency. Cloud workloads, container hosts, and on-premises servers are all in scope.

The CrowdSec incident rounds out today's briefing with a stark reminder about supply chain risk and identity hygiene. An attacker leveraged compromised employee credentials obtained through a TanStack npm package compromise to access CrowdSec's GitHub organization and exfiltrate 170 private repositories. The attack vector here was not a zero-day — it was a development dependency that had been poisoned, combined with credentials that were apparently still valid for a departed or compromised employee. The result was a significant intellectual property and potentially sensitive configuration data breach.

Defensive priorities for today:

- Patch SolarWinds ARM immediately to eliminate CVE-2026-28326; confirm no ARM management interfaces are reachable from untrusted segments and review ARM audit logs for anomalous access patterns.

- Identify all Orkes Conductor deployments across your environment, apply the vendor patch for CVE-2026-58138 without delay, and place network controls in front of any Conductor API endpoints that are currently internet-accessible.

- Audit Linux kernel versions across your entire fleet — cloud, on-premises, and containerized — and prioritize patching for CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266. Enable kernel live patching where supported to reduce downtime risk.

- Review all GitHub organization members and OAuth app authorizations. Revoke access for any accounts belonging to former employees or contractors. Enforce phishing-resistant MFA on all developer accounts and audit third-party npm dependencies for unexpected modifications.

- Implement or review software composition analysis tooling in your CI/CD pipelines to detect compromised or tampered packages before they reach production environments.

- Correlate endpoint and network telemetry for signs of post-exploitation activity: unusual outbound connections from ARM or Conductor hosts, unexpected kernel module loads, and anomalous GitHub API activity.

Today's incidents collectively illustrate that attackers are simultaneously targeting enterprise tooling, foundational infrastructure, and the development ecosystem. No single control is sufficient. Defense in depth — patching, network segmentation, identity hygiene, and continuous monitoring — remains the only reliable posture.

This briefing is informational and intended to supplement, not replace, official vendor advisories and CISA guidance.