Update Orkes Conductor to version 3.30.2 or later immediately. Apply the security update provided by Orkes. Monitor for further advisories from Orkes and Fortinet. If immediate updating is not possible, consider network segmentation and access controls to limit exposure until patching can be completed.
Quick answers
What is CVE-2026-58138?
Update Orkes Conductor to version 3.30.2 or later immediately. Apply the security update provided by Orkes. Monitor for further advisories from Orkes and Fortinet. If immediate updating is not possible, consider network segmentation and access controls to limit exposure until patching can be completed.
How severe is CVE-2026-58138?
critical, CVSS 9.8
Is CVE-2026-58138 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-58138 be mitigated?
Update Orkes Conductor to version 3.30.2 or later immediately. Apply the security update provided by Orkes. Monitor for further advisories from Orkes and Fortinet. If immediate updating is not possible, consider network segmentation and access controls to limit exposure until patching can be completed.
CVSS
9.8
Vendor
Orkes
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Orkes Conductor
Mitigation
Update Orkes Conductor to version 3.30.2 or later immediately. Apply the security update provided by Orkes. Monitor for further advisories from Orkes and Fortinet. If immediate updating is not possible, consider network segmentation and access controls to limit exposure until patching can be completed.
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in the Orkes Conductor workflow platform is being actively exploited in the wild. The flaw affects versions before 3.30.2 and carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3. Fortinet researchers confirmed the exploitation, urging immediate patching to version 3.30.2 or later.