Deltabridge Intelligence

Latest threat intelligence briefs

One living dossier per threat, kept current as new material emerges. Each brief is synthesised and correlated from 300+ sources by Athena, Deltabridge’s intelligence analyst.

Brief·2 sources19 Sept 2026

CVE-2026-82560 Exposes Perl Pod::Text To Resource Exhaustion Attack

CVE-2026-82560 affects Pod::Text versions prior to 6.1.1 in the podlators distribution for Perl, allowing a remotely initiated attack that causes CPU and memory exhaustion. The flaw was disclosed by the CPAN Security Group on 19 September 2026 and has been rated problematic. The vulnerability is triggered when a specially crafted POD document uses deeply nested =over directives, driving the calculated margin to the output width and causing the wrap function in lib/Pod/Text.pm to consume excessive resources. No exploit code has been observed in the wild at this time, and the attack vector does not require authentication or local access. Affected users should upgrade the podlators distribution to version 6.1.1 or later. Systems relying on Perl toolchains to process untrusted POD input, such as documentation build pipelines or package management utilities, carry the most practical risk from this vulnerability.
  1. 19 Sept 2026
    CVE-2026-82560 Disclosed via CPAN Security Group Advisory
  2. 19 Sept 2026
    VulDB Entry Published For CVE-2026-82560
vulnerability-disclosurepatch-management
Brief·2 sources19 Sept 2026

CVE-2026-78030 Enables Remote Code Injection Via Perl DBI Module Loading

CVE-2026-78030 is a critical code injection vulnerability affecting DBI versions before 1.653 for Perl, disclosed on 19 September 2026 by the CPAN Security Group. The flaw arises from the DBD::DBM component's failure to validate the dbm_type and dbm_mldbm attributes before passing them to Perl's require function, allowing arbitrary module loading. The vulnerability permits remote code injection without requiring local access, making any Perl application that exposes these DBD::DBM parameters to attacker-controlled input a viable target. At the time of disclosure, no public exploit has been observed, though the attack vector is remotely exploitable and the mechanics are straightforward once an attacker identifies an exposed interface. The CPAN Security Group has coordinated the disclosure alongside the release of DBI 1.653, which addresses the flaw. Administrators running affected Perl environments are advised to upgrade immediately, as the simplicity of the underlying issue raises the likelihood that working exploits will emerge in the near term.
  1. 19 Sept 2026
    CVE-2026-78030 Publicly Disclosed by CPAN Security Group
  2. 19 Sept 2026
    VulDB Rates CVE-2026-78030 as Critical, Confirms Remote Attack Vector
vulnerability-disclosurepatch-managementinitial-access
Brief·2 sources19 Sept 2026

CVE-2026-28326 Patched In SolarWinds ARM Enabling Unauthenticated RCE

SolarWinds has issued security updates to remediate CVE-2026-28326, a high-severity flaw residing in Access Rights Manager (ARM) stemming from hard-coded credentials embedded within the product. The vulnerability carries a CVSS score of 8.8 and affects all ARM versions up to and including 2026.2. Successful exploitation would permit an unauthenticated remote attacker to achieve remote code execution on affected systems without any prior authentication. Patches were disclosed publicly on 17 September 2026, with SolarWinds releasing fixes two days later on 19 September 2026. No exploit code is currently reported as available in the wild, though the unauthenticated nature of the attack vector makes this a target of significant concern. Given SolarWinds' history as a high-value target for sophisticated threat actors, organisations running ARM 2026.2 or earlier should treat patch application as a priority. The hard-coded credentials mechanism presents a straightforward attack path, and the risk of exploitation is likely to increase as technical details become more widely circulated.
  1. 19 Sept 2026
    SolarWinds releases security patch for ARM
  2. 17 Sept 2026
    CVE-2026-28326 registered on VulDB
vulnerability-disclosurepatch-managementinitial-access
Brief·2 sources19 Sept 2026

CVE-2026-58138 Actively Exploited In Orkes Conductor RCE Attacks

A critical unauthenticated remote code execution vulnerability tracked as CVE-2026-58138 in the Orkes Conductor workflow orchestration platform is actively exploited in the wild, with confirmation from Fortinet. The flaw carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, placing it among the highest-severity vulnerability classes. Affected versions span Orkes Conductor 3.21.21 through 3.30.1, with version 3.30.2 containing the patch. Attackers are exploiting the vulnerability via inline workflow definitions, a mechanism that allows arbitrary code execution without any prior authentication. The absence of an authentication requirement means any network-accessible instance of Orkes Conductor is potentially reachable by a threat actor with no credentials, dramatically lowering the barrier to initial exploitation. Organisations running exposed or internet-facing deployments face the highest risk. With active exploitation confirmed, remediation is time-critical. Security teams should prioritise patching to version 3.30.2 immediately and audit exposed instances for signs of compromise, particularly looking for unusual workflow execution activity or unexpected outbound connections.
  1. 19 Sept 2026
    Fortinet confirms in-the-wild exploitation; The Hacker News reports
  2. 18 Sept 2026
    SecurityWeek reports active exploitation of CVE-2026-58138
zero-day-exploitvulnerability-disclosurepatch-managementinitial-access
Brief·3 sources19 Sept 2026

CVE-2025-39682 Added To CISA KEV Catalog Following Active Exploitation

CVE-2025-39682, a CVSS 9.8-rated flaw in the Linux kernel TLS receive path, has been added to CISA's Known Exploited Vulnerabilities (KEV) catalogue following confirmed evidence of active exploitation in the wild. The vulnerability arises from an improper check for unusual or exceptional conditions in the kernel's TLS processing logic, a class of flaw that has historically enabled privilege escalation and remote code execution in susceptible environments. CISA's addition to the KEV catalogue on 18 September 2026 triggers mandatory remediation timelines for Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive (BOD) 26-04. CISA explicitly characterised this vulnerability type as a frequent attack vector for malicious cyber actors, citing significant risk to the federal enterprise. The urgency of federal guidance signals that exploitation is unlikely to remain confined to government-adjacent targets.
  1. 19 Sept 2026
    CISA Flags CVE-2025-39682 Alongside Two Further Linux Kernel Flaws
  2. 18 Sept 2026
    CISA Adds CVE-2025-39682 to Known Exploited Vulnerabilities Catalogue
zero-day-exploitvulnerability-disclosurepatch-managementcritical-infrastructurecloud-security
Brief·4 sources18 Sept 2026

Gyazo Server Vulnerability Exploited To Expose 23 Million User Records

Gyazo, the image-sharing platform operated by Kyoto-based Helpfeel, has confirmed a significant data breach following the exploitation of a vulnerability in its image upload server. Attackers accessed approximately 23.62 million user records, including email addresses and password hashes, alongside roughly 490 million image metadata records predominantly relating to images uploaded before January 2019. The breach was disclosed publicly on 17 September 2026 via a company notice. The image metadata exposure is particularly consequential: the leaked records include the IDs that compose Gyazo image links, meaning attackers could reconstruct or enumerate direct URLs to user-uploaded images. Helpfeel has begun notifying affected users and is engaging with the incident formally. The scale of the metadata exposure is the more significant long-term concern. While the user record count of 23.62 million is itself substantial, the 490 million image metadata records create a secondary risk surface: enumeration attacks against still-live image URLs, potential re-identification of pseudonymous users, and targeted phishing using exposed email addresses combined with knowledge of a victim's uploaded content.
  1. 18 Sept 2026
    BleepingComputer and SecurityAffairs report exploitation details
  2. 17 Sept 2026
    Helpfeel publishes breach notification for Gyazo
data-breachvulnerability-disclosurecredential-theftinitial-access
Brief·3 sources18 Sept 2026

CVE-2026-85889 Patched In Azure AI Foundry Privilege Escalation Disclosure

CVE-2026-85889 is a CVSS 10.0 maximum-severity elevation of privilege vulnerability in Microsoft Azure AI Foundry, disclosed and patched by Microsoft on 17 September 2026. The flaw stems from missing authentication for a critical function, permitting an unauthenticated remote attacker to elevate privileges over a network without any user interaction. Microsoft has confirmed the fix was applied at the service level. Because Azure AI Foundry is a managed cloud service, no customer action is required. There is no evidence of exploitation in the wild at the time of disclosure, and no public proof-of-concept exploit has been observed. The CVSS 10.0 score reflects the combination of network-accessible attack surface, zero authentication requirement, and the severity of the privilege escalation outcome. Organisations consuming Azure AI Foundry workloads should verify service-side patch status through the Microsoft Security Response Center advisory and monitor for any anomalous activity in their AI Foundry environments as a precautionary measure.
  1. 18 Sept 2026
    The Hacker News Reports Microsoft Patch for Maximum-Severity Azure AI Foundry Flaw
  2. 17 Sept 2026
    Microsoft MSRC Publishes CVE-2026-85889 Advisory
  3. 17 Sept 2026
    VulDB Catalogues CVE-2026-85889 With No Known Exploit
vulnerability-disclosurecloud-securityprivilege-escalationpatch-managementai-threats
Brief·5 sources18 Sept 2026

RatHat Android Trojan Uses AI To Automate Credential Theft

RatHat is a newly discovered Android trojan attributed to China-based operators by Zimperium researchers, publicly disclosed on 17–18 September 2026. The malware combines an AI-powered screen-control subsystem with Android Debug Bridge (ADB) abuse and Accessibility Services hijacking to give operators deep, persistent control of compromised devices without requiring constant manual interaction. Distributed via targeted smishing campaigns and malvertising links pointing to deceptive third-party download portals, RatHat is designed to steal banking credentials, authentication codes, and screen-lock PINs. Its most notable persistence mechanism abuses ADB to retain a shell session even after the malicious application is uninstalled by the victim. The combination of AI-assisted device navigation, anti-removal persistence, and a financially motivated operator profile makes RatHat a significant threat to mobile banking users. The threat is assessed as actively evolving, with the smishing-led distribution model suggesting deliberate victim targeting rather than indiscriminate spray-and-pray deployment.
  1. 18 Sept 2026
    Follow-on coverage expands technical picture
  2. 17 Sept 2026
    RatHat disclosed by Zimperium researchers
malwaremobile-threatscredential-theftai-threatsnation-state
Brief·2 sources18 Sept 2026

CVE-2026-77179 Enables Docker Sandbox Escape To macOS Host Files

A critical container escape vulnerability, CVE-2026-77179, was disclosed by Docker on 15 September 2026, affecting Docker Sandboxes versions up to and including 0.41.x on macOS. The flaw allows malicious code running inside a virtio-fs-backed virtual machine to traverse outside the shared project directory and read or modify arbitrary files on the host filesystem, operating with the full privileges of the host account running the VM. The vulnerability is rooted in a symlink-following weakness in the virtio-fs host server component. An attacker who can execute code inside the guest environment can craft symlinks that the host server resolves without adequate boundary enforcement, yielding arbitrary file read and write on the macOS host. No public exploit has been confirmed at the time of disclosure, though the severity of the primitive makes weaponisation a realistic near-term prospect. Docker has advised all users to upgrade the affected component immediately. Given that Docker Sandboxes is commonly used in developer workflows, the affected population spans individual developers through to enterprise engineering teams, where a compromised development environment could serve as a stepping-stone into broader internal systems.
  1. 17 Sept 2026
    The Hacker News publishes technical coverage of the container escape
  2. 15 Sept 2026
    Docker discloses CVE-2026-77179 and advises immediate upgrade
vulnerability-disclosurepatch-managementzero-day-exploitinitial-access
Brief·2 sources17 Sept 2026

CVE-2026-15688 Exposes Mitsubishi Electric GX Works3 Authentication Bypass

CVE-2026-15688 is a high-severity authentication bypass vulnerability affecting Mitsubishi Electric GX Works3 and the bundled Motion Control Settings software, across all versions. Assigned a CVSS v3 score of 8.8, the flaw stems from an incorrect implementation of an authentication algorithm that allows a local attacker to authenticate successfully using an invalid block password by manipulating executable memory at runtime. CISA published an ICS advisory on 17 September 2026, classifying the affected product under the Critical Manufacturing critical infrastructure sector. All deployed versions worldwide are confirmed affected. At the time of advisory publication, no public exploit code had been identified, though the nature of the vulnerability means that an attacker with local access to an engineering workstation running GX Works3 could view, tamper with, destroy, or delete control programs without legitimate credentials. The vulnerability is particularly significant given GX Works3's role as a programmable logic controller (PLC) engineering environment used in industrial automation globally. Successful exploitation could give an attacker direct control over operational technology (OT) processes, with potential consequences ranging from production disruption to physical process manipulation.
  1. 17 Sept 2026
    CISA Publishes ICS Advisory ICSA-26-260-02 for CVE-2026-15688
  2. 17 Sept 2026
    VulDB Catalogues CVE-2026-15688 as Improper Authentication Flaw
vulnerability-disclosurecritical-infrastructuremanufacturinginitial-accessprivilege-escalation

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.