IncidentsCritical Orkes Conductor flaw exploited in live attacks
An unauthenticated remote code execution bug tracked as CVE-2026-58138 is being used against the workflow orchestration platform, SecurityWeek reported.
18 Sept 2026
CVE-2026-58138, an unauthenticated remote code execution vulnerability in Orkes Conductor exploitable via inline workflow definitions, is being actively exploited by attackers.
Disclosed 18 September 2026 · Record updated 18 September 2026
Attackers are exploiting an unauthenticated RCE vulnerability in Orkes Conductor via inline workflow definitions.
IncidentsAn unauthenticated remote code execution bug tracked as CVE-2026-58138 is being used against the workflow orchestration platform, SecurityWeek reported.
18 Sept 2026