Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

Critical Orkes Conductor flaw exploited in live attacks

An unauthenticated remote code execution bug tracked as CVE-2026-58138 is being used against the workflow orchestration platform, SecurityWeek reported.

By The Agentic Times ·

A conductor's baton shatters mid-performance, releasing invisible threads that puppet the entire orchestra's instruments without permission.
A conductor's baton shatters mid-performance, releasing invisible threads that puppet the entire orchestra's instruments without permission. · Illustration: The Agentic Times

A critical vulnerability in Orkes Conductor, the workflow orchestration platform from vendor Orkes, is being exploited in attacks, SecurityWeek reported on 18 September 2026.

The flaw is tracked as CVE-2026-58138. According to SecurityWeek, it is an unauthenticated remote code execution vulnerability, meaning an attacker does not need valid credentials to run their own code on an affected system. The report says attackers can exploit it via inline workflow definitions.

That detail matters for anyone running agentic or automated pipelines. Conductor is used to orchestrate workflows, and inline workflow definitions are workflow logic supplied directly in a request rather than registered in advance. If that input path can reach code execution without authentication, the orchestrator itself becomes the entry point rather than the thing being protected.

The practical exposure depends on where the software sits. Orchestration services are often deployed inside a trusted network boundary on the assumption that only internal callers reach them, and they typically hold the credentials, tokens and connection details needed to drive the systems they coordinate. Any instance reachable from an untrusted network should be treated as a priority for review, based on the unauthenticated nature of the bug described by SecurityWeek.

SecurityWeek's report does not state which versions are affected, when exploitation began, how many organisations have been hit, or what the attackers did after gaining access. It also does not describe the underlying cause of the bug beyond the inline workflow definition exploitation path. The root cause is not yet established in the available reporting. No patch details, mitigations or workarounds are included in the report.

Because the details available are limited, defenders are working with an incomplete picture. The confirmed points are narrow: the identifier, the vulnerability class, the affected product and vendor, the exploitation vector, and the fact that attacks are under way as of 18 September 2026. Anything further, including the scale of the campaign or who is behind it, is not supported by the reporting so far.

Operators of Orkes Conductor should check vendor advisories directly for version information and fix guidance, as this article cannot confirm any that have been published. Teams that cannot immediately patch may wish to audit which networks and services can reach their Conductor endpoints, and review logs for unexpected workflow submissions, particularly inline definitions from unfamiliar sources. Given the vulnerability requires no authentication, access controls in front of the service are the main lever available until a fix is confirmed.

The Agentic Times will update this report if Orkes publishes an advisory or if further technical detail emerges on the exploitation activity.

Sources

  1. securityweek.comhttps://securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks