chiprook
← Security
SecuritySeptember 18, 2026, 15:42

Critical Orkes Conductor vulnerability exploited in attacks

CVE-2026-58138 (CVSS 9.8) in Orkes Conductor allows unauthenticated remote code execution via inline workflow tasks. A patch shipped in June in version 3.30.2, a PoC appeared in August, and attacks have been observed since August 21; Fortinet blocked about 1,300 attempts on September 8-9.

Critical Orkes Conductor vulnerability exploited in attacks
#Orkes#Conductor#Fortinet
Read next
Security

Kaspersky finds MovieReaper trojan in pirated films, C2 hidden on Solana blockchain

Security

npm Trusted Publishing Abused to Ship GHAPPIER Loader

Security

Orchid Security Delivers AI Readiness Controls With Application-Level Kill Switches

Security

Mandiant: hijacked AI coding session spread Shai-Hulud worm across ~100 repos