Skip to content
Critical RCE Vulnerability in Orkes Conductor Under Active Exploitation

Critical RCE Vulnerability in Orkes Conductor Under Active Exploitation

First seen 18 Sep 2026, 11:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 15:58 UTC
  • CVE-2026-58138 is a critical remote code execution vulnerability in Orkes Conductor.
  • Over 6,696 attack attempts were blocked in the last week, with a 132% increase in daily activity.
  • Organizations must upgrade to Conductor 3.30.2 or later to mitigate the risk.

Attackers are targeting Orkes Conductor servers due to a critical unauthenticated remote code execution vulnerability (CVE-2026-58138) affecting its GraalVM script evaluators. FortiGuard telemetry reports a significant increase in attack attempts, with 1,290 blocked in the last 24 hours alone, marking a 132% rise in daily activity. Over the past week, 6,696 attempts were thwarted, with the highest activity originating from Germany, Hong Kong, Indonesia, the UAE, and India. The vulnerability allows attackers to submit malicious workflow definitions to the Conductor workflow API, potentially executing arbitrary OS commands. Public proof-of-concept exploit code is available, further increasing the risk of opportunistic attacks. Organizations are advised to upgrade to Conductor version 3.30.2 or later to mitigate this vulnerability. Until upgrades can be applied, restricting external access and monitoring for suspicious activity are recommended. The urgency of remediation is heightened due to the vulnerability's unauthenticated nature and remote exploitability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-30
CVE-2026-58138 published
A critical unauthenticated remote code execution vulnerability in Orkes Conductor was disclosed.
Article 1
2026-07-01
First public PoC released
Public proof-of-concept exploit code for CVE-2026-58138 was made available, increasing exploitation risk.
Article 1
2026-09-09
Threat Signal Report released
FortiGuard published a report detailing active attack attempts on Orkes Conductor servers.
Article 2
2026-09-18
Increased attack activity reported
FortiGuard blocked 1,290 attack attempts in the last 24 hours, a significant rise in activity.
Article 1

More articles in this cluster (2)

Following this threat?

Track CVE-2026-58138 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed