Critical Orkes Conductor vulnerability exploited in attacks
CVE-2026-58138 (CVSS 9.8) in Orkes Conductor allows unauthenticated remote code execution via inline workflow tasks. A patch shipped in June in version 3.30.2, a PoC appeared in August, and attacks have been observed since August 21; Fortinet blocked about 1,300 attempts on September 8-9.
- CVE-2026-58138 rated CVSS 9.8 — unauthenticated RCE
- Patch released in June in Orkes Conductor 3.30.2
- Attacks in the wild since August 21, PoC since early August
- Fortinet blocked ~1,300 exploitation attempts on September 8-9
Read next
Security