CyberSecurity News
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
AI summary
A critical vulnerability in the Orkes Conductor workflow platform is being actively exploited. The issue, identified as CVE-2026-58138, has a high severity score and allows for unauthenticated remote code execution. This vulnerability affects Orkes Conductor versions 3.21.21 through 3.30.2. Fortinet has reported that the vulnerability is being exploited in the wild. The vulnerability enables remote code execution without requiring authentication.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

