Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in the Orkes Conductor workflow platform is being actively exploited in the wild. The flaw affects versions before 3.30.2 and carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3. Fortinet researchers confirmed the exploitation, urging immediate patching to version 3.30.2 or later.




















