Critical Orkes Conductor Vulnerability Exploited in Attacks
Reported exploitedConductorOur summary
Attackers are exploiting CVE-2026-58138, a CVSS 9.8 remote code execution vulnerability in Orkes Conductor that can be triggered without authentication through malicious workflow definitions. The flaw was fixed in Conductor 3.30.2; organizations should update, limit access to workflow API endpoints, and investigate suspicious workflow activity.
Read at SecurityWeek
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.