Cybersecurity · September 20, 2026
Fortinet researchers report active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution bug in the Orkes Conductor workflow orchestration platform. The flaw, carrying a CVSS score of 9.8, affects versions from 3.21.21 up to 3.30.2 and lets attackers run arbitrary code without needing to log in first. Teams running Conductor should patch immediately given the confirmed in-the-wild attacks.
// source: thehackernews.com ↗