Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Security

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

The Hacker News · Sep 19, 2026

Back to News
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Security September 19, 2026

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.