Home / Sep 20, 2026 / Story
0
#3 The Hacker News general September 19, 2026 at 08:18 UTC

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

By [email protected] (The Hacker News)

AI Summary

CVE-2026-58138 (CVSS 9.8), an unauthenticated RCE flaw in Orkes Conductor versions prior to 3.30.2, is being actively exploited in the wild according to Fortinet, allowing remote attackers to execute arbitrary code via inline workflow definitions without any authentication. Organizations running Orkes Conductor 3.21.21 or earlier should prioritize patching immediately.

Relevance score: 86.0/100

# More from September 20