National Cyber Warfare Foundation (NCWF)

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild


0 user ratings
2026-09-19 08:49:05
milo
Blue Team (CND)
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.

The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.

"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.