Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Cybersecurity · September 20, 2026

Cybersecurity·thehackernews.com

Fortinet researchers report active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution bug in the Orkes Conductor workflow orchestration platform. The flaw, carrying a CVSS score of 9.8, affects versions from 3.21.21 up to 3.30.2 and lets attackers run arbitrary code without needing to log in first. Teams running Conductor should patch immediately given the confirmed in-the-wild attacks.

// source: thehackernews.com ↗

Back to Blog