Search
Find merged stories by title or summary.
InfoSec News Nuggets – 09/21/2026
Gyazo server flaw exploited to steal 23.6 million user records The cloud-based screenshot platform Gyazo, operated by Helpfeel, confirmed that attackers exploited a server vulnerability on September 11 to access its database and steal roughly 23. 6 million user records, including names, emails, password hashes, device and session IDs, and some connected-account tokens, along with 490 million image metadata records tied mostly to pre-2019 uploads. The company took the service offline for maintenance, patched the flaw, and is notifying affected users while urging them to change reused passwords. Critical Orkes Conductor Vulnerability Exploited in Attacks A critical, unauthenticated remote code execution flaw in the open-source workflow orchestration platform Orkes Conductor, tracked as CVE-2026-58138 with a CVSS score of 9.
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3. 1 score: 9. 8/CVSS v4 score: 9. 3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3. 21. 21 before 3. 30. 2 contains an unauthenticated remote code execution vulnerability that allows remote
Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek .
You've reached the end of current stories for this search.
