Critical RCE Vulnerability in Orkes Conductor Under Active Exploitation
Article Content
- •CVE-2026-58138 is a critical remote code execution vulnerability in Orkes Conductor.
- •Over 6,696 attack attempts were blocked in the last week, with a 132% increase in daily activity.
- •Organizations must upgrade to Conductor 3.30.2 or later to mitigate the risk.
Attackers are targeting Orkes Conductor servers due to a critical unauthenticated remote code execution vulnerability (CVE-2026-58138) affecting its GraalVM script evaluators. FortiGuard telemetry reports a significant increase in attack attempts, with 1,290 blocked in the last 24 hours alone, marking a 132% rise in daily activity. Over the past week, 6,696 attempts were thwarted, with the highest activity originating from Germany, Hong Kong, Indonesia, the UAE, and India. The vulnerability allows attackers to submit malicious workflow definitions to the Conductor workflow API, potentially executing arbitrary OS commands. Public proof-of-concept exploit code is available, further increasing the risk of opportunistic attacks. Organizations are advised to upgrade to Conductor version 3.30.2 or later to mitigate this vulnerability. Until upgrades can be applied, restricting external access and monitoring for suspicious activity are recommended. The urgency of remediation is heightened due to the vulnerability's unauthenticated nature and remote exploitability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-58138 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical CVE-2026-58138 in Orkes Conductor Exploited in the Wild A critical vulnerability, CVE-2026-58138, in Orkes Conductor allows unauthenticated remote code execution. This flaw, affecting versions prior to 3.30.2, enables attackers to submit malicious JavaScript or Python expressions via the workflow API endpoint. Exploitation can invoke arbitrary system commands due to the…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…