FortiGuard Threat Signal / Outbreak Alert (released 9 September 2026; SecurityWeek coverage 18 September) tracks active exploitation of CVE-2026-58138 in Orkes Conductor / conductor-oss: unauthenticated remote code execution via GraalVM script evaluators. Attackers POST a workflow definition with hostile INLINE (also LAMBDA, DO_WHILE, SWITCH) JavaScript or Python expressions to the workflow API; evaluators configured with HostAccess.ALL / unrestricted host access escape the sandbox and run OS commands as the Conductor process (often root). Open-source Conductor leaves the workflow API unauthenticated by default. NVD/VulnCheck describe affected range Conductor 3.21.21 before 3.30.2; complete fix in 3.30.2 (partial denyAccess blocklist on 3.30.0/3.30.1 is incomplete). Public PoC exists (incl. Exploit-DB / lab repos targeting ~3.23.0). FortiGuard telemetry: ~1,290 IPS blocks in 24h (rising) and ~6,696 over seven days; top observed sources Germany, Hong Kong, Indonesia, UAE, India. Empirical Security cited in-the-wild from ~21 August after August PoC. CVSS 9.8 reported (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Not claiming Australia KEV. Primary: FortiGuard threat signal; secondary: SecurityWeek 18 Sep / NVD.
FortiGuard — Orkes Conductor evaluator RCE Threat Signal (CVE-2026-58138)
Palo Alto Networks PSIRT CVE-2026-0307 (published 9 September 2026, updated 16 September 2026): multiple local privilege-escalation vulnerabilities in the GlobalProtect app (CWE-426 untrusted search path) let a local low-privileged user reach NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux, then run arbitrary commands with administrative privileges. iOS, Android and ChromeOS are not impacted. No special configuration required. Vendor CVSS-BT 5.9 MEDIUM (CVSS 4.0); CVSS-B 8.5; exploit maturity UNREPORTED; urgency MODERATE. Palo Alto Networks says it is not aware of malicious exploitation. Fixes: GlobalProtect 6.3.3-h15+ (Windows/macOS/Linux; Linux ETA ~17 Sep, Windows/macOS ETA ~28 Sep on the advisory), 6.2.8-h14+ (Windows/macOS), 6.0.15+ (Linux/macOS; Windows ETA ~29 Oct). NGFW customers must also upgrade PAN-OS and Prisma Access tenants to builds listed in the Solution table (e.g. PAN-OS 12.2.3, 12.1.10 / 12.1.7-h5 / 12.1.4-h10, and listed 11.2/11.1/10.2 hotfixes). Prisma Access scheduled maintenance upgrades; on-demand via Support. Distinct from desk cards cve-2026-0299 and cve-2026-0251. Primary: Palo Alto Networks PSIRT.
Check Point support articles sk1000117 and sk1000118 (disclosed 9 September 2026) cover two critical VPN-certificate handling flaws the vendor found internally. CVE-2026-85102 (sk1000117) is authentication bypass and remote code execution in Remote Access and Site-to-Site VPN on Quantum Security Gateway when certificate trust is not validated correctly during VPN negotiation. CVE-2026-85103 (sk1000118) is a heap-based buffer overflow while decoding the ASN.1 structure of a VPN certificate that can yield unauthenticated RCE on Quantum Security Gateway and Quantum Security Management. Both carry CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) per the CVE records. Vendor reporting at disclosure said no evidence of in-the-wild use. UPDATE 12 September 2026: the Dutch NCSC (alert) assesses likelihood of exploitation and potential impact as high and expects exploitation attempts soon; no public PoC reported at that writing. NCSC urges immediate updates and, for Site-to-Site VPN, limiting peers to trusted IPs. LivePatch Take 24 / matching Jumbo builds as in the SK articles; R82.20 unaffected. Affected Jumbo trains cited in public writeups include R82.10 Take 43 or below, R82 Take 125 or below, and R81.20 Take 165 or below (plus older EOS trains in third-party summaries); R82.20 called unaffected. Apply the matching Jumbo Hotfix / LivePatch from the SK articles. Primary: Check Point sk1000117; also sk1000118; wire: The Hacker News (10 Sep 2026).
CERT/CC and BleepingComputer (9 September 2026) warn that Skullcandy Dime 3 earbuds (model S2DCW) on firmware 1.0.0.28 accept Bluetooth pairing from nearby unpaired devices without user interaction, PIN, or case access. Issue tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK. Skullcandy says fixed in firmware 1.0.0.30, but end users have no supported update path via the Skullcandy app. Nearby attacker can hijack the audio link. Broader Airoha-based headset class affected per ERNW/TROOPERS research. Primary wire: BleepingComputer citing CERT/CC.
Wiz Research (Amitai Cohen & Yaara Shriki, 9 September 2026; also THN same day) scanned ~3,074 internet-facing LiteLLM AI gateways: 294 (9.6%) accepted the docs/Docker default master key sk-1234 or required no authentication (191 of those had no key at all). Default/missing master key grants admin and exposes every configured LLM provider API key (LLMjacking), and can chain to post-auth custom-code-guardrail RCE CVE-2026-59821 (fixed v1.82.0) for root-in-container when still on vulnerable builds. Same research covers MCP auth bypass CVE-2026-59822 (already on this desk; CISA KEV; Wiz honeypot exploitation). LiteLLM still ships sk-1234 as the example/default in common install paths. Mitigate: set a unique strong master key immediately; upgrade past 1.82.0/1.84.0; review custom guardrails and pass-through endpoints. Category tech (AI gateway stack). Primary: Wiz; wire: THN. Distinct card from cve-2026-59822.
SecurityWeek (9 September 2026) covers Tuesday advisories from AMD, Arm, and Nvidia. AMD-SB-6034: CVE-2026-43603 NULL pointer dereference in the Linux GPU kernel driver (clear operation under compute conditions) leading to kernel crash/DoS; CVSS 4.0 6.9 (AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/...); CWE-476; credited SecMate. Mitigations: Radeon Software for Linux 26.13 for several EPYC 4004/4005 lines (20 Jul 2026); embedded EPYC/Ryzen lines targeted October 2026 per AMD bulletin. Arm advisory covers nine Mali GPU issues (Valhall / Arm 5th Gen / Bifrost kernel and userspace) enabling use-after-free, kernel info leak, or DoS. Nvidia Triton Inference Server for Linux: two high-severity defects (DoS; info disclosure/tamper/DoS). Primary: AMD bulletin; Arm/Nvidia linked from SecurityWeek (Arm/Nvidia pages 403 from this pass).
The Hacker News (9 September 2026) reports Alby warned of a critical flaw in self-hosted Alby Hub (Lightning bitcoin wallet) that could let an attacker take over a wallet and send funds — only where the Hub management interface was reachable from the internet. Affected: v1.7.0 through v1.18.5 (pre-August 2025 builds); fixed from v1.19.0 (first fixed release 29 August 2025); current recommended v1.24.0. Alby says one user affected so far; technical details withheld pending responsible disclosure. Guidance: remove external reachability first (e.g. bind 127.0.0.1), then upgrade; if exposed on an affected build, change unlock password after update and contact security@getalby.com. Primary wire: THN citing Alby; releases: GitHub getAlby/hub.
BleepingComputer (9 September 2026) reports anonymous researcher Nightmare Eclipse released a ShieldCrash proof-of-concept against Microsoft Defender immediately after September 2026 Patch Tuesday. The researcher claims ShieldCrash bypasses the ShieldBreak elevation issue patched as CVE-2026-69414 and demonstrates arbitrary file read as SYSTEM on fully patched Windows 10, Windows 11, and Windows Server, without write access to the compromised system. ShieldBreak itself followed RoguePlanet (disclosed June, patched July). Microsoft had not commented to BleepingComputer at publish. Treat as a local privilege-escalation research drop / incomplete patch claim — not a remote wormable CVE. No Australian exploitation signal on this pass. Primary: BleepingComputer.
SecurityWeek (9 September 2026) summarises Fortinet's Tuesday patch set of ten vulnerabilities. Critical CVE-2026-84390 (CVSS 9.6) is inclusion of sensitive information in source code on the FortiMonitorOnSight web portal — a remote unauthenticated attacker can bypass authentication via a forged or reused JWT. Critical CVE-2026-84388 (CVSS 9.1) is improper authentication in the Fortinet Privileged Access Agent Chrome extension — a remote unauthenticated attacker can proxy a victim's browser traffic if the user visits a malicious site. Fortinet says full remediation needs FortiPAM 1.9.1 or 1.8.4 plus Chrome extension 8.0.1.123 or newer. Same batch includes high issues in FortiSandbox (CVE-2026-26084) and FortiOS/FortiProxy. Primary wire: SecurityWeek; confirm builds on FortiGuard PSIRT.
Cisco PSIRT advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2 covers CVE-2026-20079, a maximum-severity (CVSS 10.0) authentication-bypass in Cisco Secure Firewall Management Center (FMC) and related management paths. Improper process creation at boot lets an unauthenticated remote attacker send crafted HTTP requests to the web interface and execute scripts/commands as root. Cisco updated the advisory on 9 September 2026 to state PSIRT became aware of active exploitation in August 2026 (no public attribution or start date). Cloud-hosted Security Cloud Control is already patched per Cisco; on-prem FMC has no workaround — upgrade to a fixed release. BleepingComputer (9 Sep) notes CISA added CVE-2026-20079 to the KEV catalog with FCEB remediation due 12 September 2026. Hunt guidance from related July FMC coverage includes /var/log/messages activity around /var/tmp/license.tmp. Distinct from desk cards cisco-esa-iosxr-20260902 and cisco-sd-wan-2026. Primary: Cisco PSIRT; wire: BleepingComputer. NEW 10 September 2026 (Cisco Talos “Active exploitation of Cisco Secure Firewall Management Center vulnerabilities”; BleepingComputer same day): Talos tracks three post-compromise clusters on FMC — UAT-11988 (high confidence Qilin ransomware affiliates), UAT-11823 (high confidence APT tooling overlap with Sandworm / Cyclops Blink deployment), and UAT-12197 (state-sponsored/crimeware mix). Actors abused CVE-2026-20079 and companion CVE-2026-20316 (static low-privileged credentials; CVSS 5.3 per wire, Cisco High because it chains with other FMC bugs) to plant web shells, steal AD/MySQL credentials, stand up SOCKS5/SSH tunnels, and in one cluster deploy Qilin ransomware. Install Cisco hotfixes for both CVEs immediately; comprehensive hardening package noted as forthcoming. Distinct companion CVE covered here rather than a sibling card.
Palo Alto Networks security advisory CVE-2026-0310 (published 9 September 2026): buffer overflow in PAN-OS XML processing lets an unauthenticated network attacker with access to the management web or dataplane interface cause DoS on VM-Series firewalls or execute arbitrary code as root on PA-Series. Vendor severity 7.2 HIGH; urgency HIGHEST; exploit maturity UNREPORTED. Panorama is impacted. Risk is reduced when management is restricted to trusted internal IPs per Palo Alto best practice. Fixed builds include PAN-OS 12.2.3; 12.1.4-h10 / 12.1.7-h5 / 12.1.10; 11.2.4-h21 / 11.2.7-h20 / 11.2.10-h14 / 11.2.13-h2; 11.1.4-h36 / 11.1.6-h38 / 11.1.7-h10 / 11.1.10-h33 / 11.1.13-h12 / 11.1.16-h2; 10.2.7-h37 / 10.2.10-h40 / 10.2.13-h24 / 10.2.16-h10 / 10.2.18-h10 (confirm against the live advisory for your branch). Prisma Access / Cloud NGFW called medium severity on the same advisory and are scheduled for maintenance upgrades. Primary: Palo Alto Networks advisory.
SecurityWeek (9 September 2026) reports Schneider Electric, Siemens, AVEVA, and Rockwell September ICS Patch Tuesday advisories. Schneider published four new advisories and updated four older ones: most severe new issue is critical authentication vulnerability CVE-2026-3869 (CVSS 9.2) in Modicon M580 and Modicon M580 Safety controllers; also high-severity fixes in PowerLogic T300 / Easergy T300 RTU and EcoStruxure IT Data Center Expert, and a medium issue in SCADAPack x70; MC80 patches added to older advisories. Siemens issued nine new advisories (seven on 8 Sep) including critical issues in Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager/SIPLANT, plus Copy Fail Linux kernel CVE-2026-31431 (CVSS 7.8) updates. AVEVA PIMBoards/Enterprise SCADA and Rockwell RSLinx/FactoryTalk/CompactLogix advisories also in the same window. Schneider Electric's notifications index returned HTTP 403 from this desk pass — wire URL is primary until the SEVD pages are reachable. OT/ICS operators should pull vendor bulletins and patch by asset criticality.