Employee offboarding access control lapses create lasting breach exposure for small businesses. The CrowdSec supply chain attack, triggered by a compromised former employee account months after departure, shows why immediate credential revocation and ongoing access audits are critical to your security posture.
In today's cyber news update for September 19, 2026, we cover five critical security issues affecting small businesses:
1. WordPress Click2Shell Vulnerability: A serious vulnerability in WordPress core allows attackers to gain remote code execution through a single malicious link. The exploit chain starts with a theme-preview weakness that silently installs an attacker-chosen theme, then escalates to full server compromise. WordPress has released patches. All WordPress site owners should update immediately.
2. SolarWinds Access Rights Manager Flaw (CVE-2026-28326): SolarWinds patched a high-severity vulnerability (CVSS 8.8) in Access Rights Manager that enables unauthenticated remote code execution. All versions of ARM 2026.2 and prior are affected. Businesses using this software should update to the latest version immediately.
3. Orkes Conductor Under Active Attack (CVE-2026-58138): A critical vulnerability (CVSS 9.8) in Orkes Conductor workflow platform is being actively exploited in the wild. The flaw allows unauthenticated remote code execution. Versions 3.21.21 through 3.30.1 are affected. Update to version 3.30.2 or later immediately if you use this platform.
4. CrowdSec Supply Chain Breach: Attackers stole 170 private GitHub repositories from CrowdSec after compromising a former employee's account through the May TanStack npm supply chain attack. The breach occurred on May 22 but wasn't discovered until stolen code appeared on a criminal forum on September 16. This highlights the critical importance of immediately revoking all system access when employees leave, and the long-term risks of supply chain compromises.
5. Elevation Hospice Data Breach: Elevation Hospice of Utah disclosed a breach exposing Social Security numbers, medical records, and other sensitive information for 437 individuals. This incident underscores the ongoing targeting of healthcare providers and the need for robust data protection measures, encryption, access controls, staff training, and regular backups.
Key takeaways for small business owners: Keep all software updated, especially WordPress and SolarWinds products; implement proper employee offboarding procedures that include immediate access revocation; and if you handle sensitive data, audit your security controls now.
Why Does Employee Offboarding Access Control Matter for Your Business?
When employees leave, delayed or incomplete access revocation turns them into dormant attack vectors. CrowdSec's breach proves this: attackers exploited a former staffer's GitHub token five months after the TanStack attack, stealing 170 private repositories and exposing the company's code on criminal forums by September 16. For SMBs in manufacturing or professional services, this pattern repeats across SolarWinds (CVE-2026-28326, CVSS 8.8) and WordPress installations. Your action: audit all vendors, cloud platforms, and internal systems today. Create a documented offboarding checklist that includes password manager access, GitHub tokens, SolarWinds credentials, and cloud admin accounts. Set a 30-day review to confirm revocation across all systems. CISA warnings consistently cite access management failures as root causes in breach timelines.
Key takeaways
- Revoke all system credentials within 24 hours of employee departure, not after the exit interview.
- Audit former employee access every 30 days for 90 days post-departure; CrowdSec's five-month lag shows attackers wait for detection to fade.
- Patch WordPress immediately (Click2Shell RCE vulnerability) and SolarWinds ARM before version 2026.2 to close concurrent attack windows.
- If you handle sensitive data (healthcare, financial records), test backups monthly and verify encryption on all stored PHI or PII.
Frequently asked questions
How long does a compromised former employee account pose a risk?
The CrowdSec case shows attackers can wait months before exploiting stolen credentials. They waited five months after compromising the account, then used it to steal code. This means access revocation is time-critical but ongoing audits are equally important; check for forgotten accounts quarterly.
What systems should be included in our employee offboarding checklist?
Start with password managers, GitHub and GitLab tokens, cloud platforms (AWS, Azure, Google Cloud), VPN access, email forwarding rules, SolarWinds and other enterprise tool accounts, and any third-party vendor portals. Create a documented step-by-step checklist and assign ownership to IT.
Should we worry about WordPress and SolarWinds patches if we're small?
Yes. WordPress Click2Shell is a remote code execution flaw in WordPress core, not a plugin, so it affects any WordPress site. SolarWinds ARM patch (CVE-2026-28326) is urgent for any SMB using it for identity management. Both allow unauthenticated attacks and should be patched this week.
What is a supply chain attack and how does it relate to offboarding?
A supply chain attack targets a trusted vendor to reach its customers. The CrowdSec breach happened because an employee's compromised account gave attackers access to private code, which they later sold or leaked. Offboarding prevents your company from becoming the weak link in someone else's supply chain.
Sources
- https://cybersecuritynews.com/click2shell-wordpress-vulnerability/
- https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
- https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
- https://cybersecuritynews.com/tanstack-supply-chain-attack/
- https://www.claimdepot.com/data-breach/elevation-hospice-2026