Find notable cyber news and cases, enriched with sources, timelines, and signals.

Orkes Conductor unauthenticated RCE (CVE-2026-58138)

Vulnerability
First reported
Last updated
Happening score
H score 46
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-58138 is an unauthenticated remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2 that is being actively exploited. Attackers can submit crafted workflow definitions with JavaScript or Python expressions to the workflow API before authentication and trigger arbitrary OS command execution. Organizations running affected versions face immediate takeover risk on exposed Conductor instances until they upgrade or isolate the API.

Related Happenings

Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program

Threat Actor Meta
H score24 First: 11.06.2026 19:50 Last: 11.06.2026 19:50 Sources 1

About this happening: Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

CISA updates KEV entry for CVE-2026-1731

Public Sector Action
H score36 First: 20.02.2026 17:45 Last: 20.02.2026 17:45 Sources 1

About this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...

BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave

Exploitation Wave
H score76 First: 12.02.2026 23:34 Last: 12.02.2026 23:34 Sources 1

About this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...

Timeline

  1. 19.09.2026 11:18 1 articles · 2h ago

    Fortinet blocks a surge of CVE-2026-58138 attack attempts

    Campaign Scope Update

    By September 9, 2026, Fortinet had blocked 1,290 attack attempts within 24 hours and nearly 7,000 attempts between September 2 and 9, 2026, with most activity originating from Germany, Hong Kong, Indonesia, the U.A.E., and India.

    Show sources
  2. 19.09.2026 11:18 2 articles · 2h ago

    Fortinet warns of active CVE-2026-58138 exploitation in Orkes Conductor

    Initial Disclosure

    Fortinet warned that attackers are actively targeting Orkes Conductor servers susceptible to CVE-2026-58138 by submitting crafted workflow definitions with JavaScript or Python expressions to the workflow API before authentication, and it advised upgrading to Conductor 3.30.2 or later or restricting external API access.

    Show sources