#3
The Hacker News
general
September 19, 2026 at 08:18 UTC
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
By [email protected] (The Hacker News)
AI Summary
CVE-2026-58138 (CVSS 9.8), an unauthenticated RCE flaw in Orkes Conductor versions prior to 3.30.2, is being actively exploited in the wild according to Fortinet, allowing remote attackers to execute arbitrary code via inline workflow definitions without any authentication. Organizations running Orkes Conductor 3.21.21 or earlier should prioritize patching immediately.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →