LIVE · cybersecurity feed
Live wire
CVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEs
CVE-2026-58138critical

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

zeroday.news ·

A critical pre-authentication remote code execution (RCE) vulnerability in the Orkes Conductor workflow orchestration platform is reportedly being actively exploited in the wild. The flaw, identified as CVE-2026-58138, carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, indicating its severe impact and ease of exploitation. Security researchers at Fortinet are credited with reporting the active exploitation.

The vulnerability specifically affects Orkes Conductor versions prior to 3.30.2, with version 3.21.21 and earlier confirmed to be susceptible. The core issue is an unauthenticated remote code execution vulnerability, meaning an attacker does not need to provide any credentials to execute arbitrary code on the affected system. This significantly lowers the bar for exploitation, making it a highly attractive target for malicious actors.

Orkes Conductor is a widely used microservices orchestration platform, designed to manage and automate complex workflows across distributed systems. Its role in critical infrastructure and business processes means that a compromise could lead to significant disruption, data breaches, or further network penetration within an organization. The platform's nature often involves handling sensitive data and controlling various backend services.

Pre-authentication RCE vulnerabilities are among the most dangerous types of security flaws. They typically arise from issues such as improper input validation, deserialization vulnerabilities, or insecure configuration defaults that allow an attacker to send specially crafted requests to a service and execute commands on the underlying operating system. The "unauthenticated" aspect means the attacker can interact with the vulnerable component directly from the network without needing to bypass any authentication mechanisms.

Mitigation for this class of vulnerability invariably involves applying the vendor-supplied patch as soon as possible. For Orkes Conductor, organizations are advised to upgrade their installations to version 3.30.2 or later to address CVE-2026-58138. In situations where immediate patching is not feasible, organizations might consider network-level controls, such as restricting access to the Conductor platform to trusted IP addresses or implementing Web Application Firewalls (WAFs) with rules designed to detect and block known exploit patterns, though these are typically temporary measures.

The active exploitation of this critical flaw underscores the ongoing threat posed by unauthenticated remote code execution vulnerabilities in widely deployed enterprise software. Such incidents highlight the importance of timely patching and robust vulnerability management programs, especially for components that are internet-facing or play a central role in an organization's operational technology or IT infrastructure. The high CVSS scores reflect the significant risk, urging immediate action from affected organizations to prevent potential compromise.

vulnerabilities in this storyCVE-2026-58138
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

nation-state

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

security

Flock Offers Employees Buyouts as Customers Flee

As dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned.

supply chain attackhigh

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A supply-chain attack on the marketing platform Brevo, formerly Sendinblue, leveraged a compromised Cloudflare API key to inject malicious code into over 100,000 websites. The attackers initially gained access through a SAML SSO vulnerability, compromising customer accounts and exporting data. After blocking the initial breach, they returned and used a stolen Cloudflare API key to deploy a malicious Worker that modified website responses at the edge, bypassing origin server security checks and distributing malware to visitors.

security

Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

ai

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks

The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.