Attackers are actively exploiting CVE-2026-58138, a critical unauthenticated remote-code-execution flaw in Orkes Conductor. Unsafe evaluation of attacker-controlled JavaScript or Python expressions in inline workflow definitions lets attackers escape GraalVM scripting restrictions and execute operating-system commands as the Conductor process—potentially with root privileges. Public exploit code, including an exploit targeting Conductor v3.23.0 published as Exploit-DB EDB-52633, preceded observed attacks; Fortinet recorded roughly 1,300 blocked exploitation attempts over September 8–9.
Orkes addressed the issue in Conductor v3.30.2 in June 2026, and organizations should urgently upgrade exposed deployments, restrict access to workflow APIs, and place instances behind firewalls. Defenders should examine systems that ran vulnerable versions for malicious workflow definitions and evidence of command execution. The issue follows an earlier related Conductor flaw, CVE-2025-26074, which enabled OS command execution through unrestricted Java-class access in v3.21.11.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
FortiGuard released a Threat Signal Report concerning active attempts to exploit CVE-2026-58138 in vulnerable Orkes Conductor deployments.
Fortinet blocked approximately 1,300 attempts to exploit CVE-2026-58138 over September 8-9, indicating ongoing opportunistic attacks against vulnerable Orkes Conductor deployments.
Empirical Security identified attacks exploiting CVE-2026-58138 in the wild after public proof-of-concept code became available.
Exploit-DB published EDB-52633, a public unauthenticated RCE exploit for CVE-2026-58138, including a working exploit targeting Conductor v3.23.0.
Orkes patched the critical unauthenticated remote-code-execution flaw CVE-2026-58138 in Conductor version 3.30.2.
MITRE published CVE-2025-26074, documenting that Orkes Conductor v3.21.11 could allow remote attackers to execute arbitrary operating-system commands through unrestricted access to Java classes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcefortiguard.fortinet.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.