Vulnerabilities · InfosecFeed Brief

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

What you need to know

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code…

Source transparency

This is an InfosecFeed curated brief based on reporting from The Hacker News. InfosecFeed does not claim ownership of the original reporting.

Read the original report at The Hacker News ↗