CVE Tools
Back to feed
Exploited in the wild Conductor rce Orkes supply-chain

Critical Orkes Conductor Vulnerability Exploited in Attacks

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Attackers are exploiting CVE-2026-58138, a CVSS 9.8 remote code execution vulnerability in Orkes Conductor that can be triggered without authentication through malicious workflow definitions. The flaw was fixed in Conductor 3.30.2; organizations should update, limit access to workflow API endpoints, and investigate suspicious workflow activity.