ZeroHour
Organization

Empirical Security

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

AI-assisted bug hunting drives record vulnerability disclosures, with 66,401 CVEs logged in 2026 so far, nearly double last year's pace, straining defenders and open-source maintainers.

WIRED's Kernel Panic newsletter reports that AI-enhanced vulnerability discovery is producing record CVE volumes: 66,401 CVEs had been recorded in 2026 as of mid-September, versus 33,512 by the same date in 2025, according to cve.icu's Jerry Gamblin. Microsoft has patched 974 CVEs this month, Oracle shipped 1,448 patches in July versus 309 in July 2025, and Chrome's two June releases included 1,072 patches, more than the prior 23 major releases combined. Mozilla found 271 Firefox vulnerabilities in a single bug-hunting sprint using Anthropic's Mythos model. Experts warn that discovery now scales with compute while remediation scales with people, risking developers and under-resourced security teams being outpaced.

WIRED · Security · 15h agoIndustry

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Unauthenticated RCE CVE-2026-58138 in Orkes Conductor is actively exploited; Fortinet blocked ~7,000 attacks; patch to 3.30.2.

Fortinet reports active in-the-wild exploitation of CVE-2026-58138 (CVSS v3.1 9.8), an unauthenticated remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Attackers submit inline workflow definitions with malicious JavaScript or Python expressions to the workflow API, escaping unsandboxed GraalVM evaluators configured with HostAccess.ALL to run arbitrary OS commands. Fortinet blocked 1,290 attempts in 24 hours as of September 9, 2026, and nearly 7,000 between September 2-9, with most activity from Germany, Hong Kong, Indonesia, the U.A.E., and India. Previdian and Empirical Security also observed exploitation since July 24, 2026.

The Hacker News · 18h agoExploit / PoC in the wild 2 sourcesCVE-2026-581381· 1 read

Related CVEs

  • Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS comma
    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.