CVE Tools

Critical Orkes Conductor Vulnerability Exploited in Attacks

SecurityWeekBy Ionut Arghire

Reported exploitedConductor

Our summary

Attackers are exploiting CVE-2026-58138, a CVSS 9.8 remote code execution vulnerability in Orkes Conductor that can be triggered without authentication through malicious workflow definitions. The flaw was fixed in Conductor 3.30.2; organizations should update, limit access to workflow API endpoints, and investigate suspicious workflow activity.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store