Orkes Conductor Evaluator Remote Code Execution
Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments. In the last 24 hours, FortiGuard IPS blocked 1,290 attack attempts, representing a 132% increase in daily activity. Over the last seven days, 6,696 attempts were blocked, with activity increasing 17% week over week. The highest volumes of observed attack activity originated from Germany, Hong Kong, Indonesia, the United Arab Emirates, and India. The vulnerability allows an unauthenticated attacker to submit a malicious workflow definition containing JavaScript or Python expressions to the Conductor workflow API. Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process. Public proof-of-concept exploit code is available, including a working exploit targeting Conductor v3.23.0. Exploit material has also been published through Exploit-DB, increasing the likelihood of opportunistic scanning and exploitation of exposed deployments.
What is the recommended Mitigation?
Organizations using affected versions should upgrade to Conductor 3.30.2 or later, which addresses the vulnerability. Until systems can be upgraded: • Restrict external access to Conductor workflow API endpoints. • Place Conductor instances behind appropriate network access controls and segmentation. • Do not expose vulnerable Conductor services directly to the Internet. • Monitor for suspicious workflow submissions and unexpected command execution originating from the Conductor process. • Review systems running vulnerable versions for signs of unauthorized command execution. Because the vulnerability is unauthenticated and remotely exploitable, Internet-exposed instances should be treated as a high priority for remediation.
What FortiGuard Coverage is available?
• FortiGuard IPS Service: Detects and blocks network-based exploitation attempts targeting the Orkes Conductor vulnerability, including malicious requests attempting to trigger remote code execution. Intrusion Prevention | FortiGuard Labs • FortiGuard Antivirus & Behavior Detection: Detects and blocks malicious files, scripts, and payloads that may be delivered following successful exploitation. • FortiGuard Web Filtering: Helps block access to known malicious infrastructure and payload-hosting locations associated with post-exploitation activity. • FortiEDR: Detects suspicious post-exploitation behavior, including unauthorized command execution, process spawning, persistence, and other activity resulting from a compromised Conductor server.
Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments. The vulnerability allows an unauthenticated attacker to submit a malicious workflow definition containing JavaScript or Python expressions to the Conductor workflow API. Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process. Public proof-of-concept exploit code is available, including a working exploit targeting Conductor v3.23.0. Exploit material has also been published through Exploit-DB, increasing the likelihood of opportunistic scanning and exploitation of exposed deployments.
View the full Outbreak Alert Report
CVE Record Information
Experienced a Breach? We're here to help
FortiGuard Threat Signal
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
