Cyber Resilience
← All news
Claimed

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Our takeFortinet reports active exploitation of CVE-2026-58138, a pre-auth RCE in Orkes Conductor (CVSS 9.8). Claimed but unconfirmed by any filing or second source; treat as unverified for now. Patch to 3.30.2 if you run it.
Sources (1)
What this means for you — Security leader:If you run Orkes Conductor, update immediately to 3.30.2 or later; the pre-auth RCE (CVE-2026-58138) is confirmed exploited in the wild.
What this means for you — Lean IT orgs:If you use Orkes Conductor for workflows, check with your provider or IT contact right away to confirm they have updated to version 3.30.2 or newer.
What this means for you — MSP:Audit all client environments running Orkes Conductor and ensure they are upgraded to 3.30.2+; the unauthenticated RCE is actively exploited.
What this means for you — Researcher:Fortinet reports active exploitation of CVE-2026-58138 (CVSS 9.8), a pre-auth RCE in Orkes Conductor <=3.21.21; fixed in 3.30.2.