Orkes Conductor unauthenticated RCE (CVE-2026-58138)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-58138 is an unauthenticated remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2 that is being actively exploited. Attackers can submit crafted workflow definitions with JavaScript or Python expressions to the workflow API before authentication and trigger arbitrary OS command execution. Organizations running affected versions face immediate takeover risk on exposed Conductor instances until they upgrade or isolate the API.
Related Happenings
Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program
Threat Actor Meta
H score24
First: 11.06.2026 19:50
Last: 11.06.2026 19:50
Sources 1
About this happening:
Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...
Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program
Threat Actor MetaAbout this happening: Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA updates KEV entry for CVE-2026-1731
Public Sector Action
H score36
First: 20.02.2026 17:45
Last: 20.02.2026 17:45
Sources 1
About this happening:
CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
CISA updates KEV entry for CVE-2026-1731
Public Sector ActionAbout this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation Wave
H score76
First: 12.02.2026 23:34
Last: 12.02.2026 23:34
Sources 1
About this happening:
CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
BeyondTrust Remote Support and Privileged Remote Access CVE-2026-1731 active exploitation wave
Exploitation WaveAbout this happening: CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access is now seeing first in-the-wild exploitation, putting exposed appliances at risk of remote...
Timeline
-
19.09.2026 11:18 1 articles · 2h ago
Honeypot exploitation attempts target Orkes Conductor
Exploitation ObservedTelemetry from honeypots recorded three exploitation attempts against Orkes Conductor on July 24, 2026, from two unique IP addresses in France and the U.S.
Show sources
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — thehackernews.com — 19.09.2026 11:18
-
19.09.2026 11:18 1 articles · 2h ago
In-the-wild exploitation reaches Orkes Conductor deployments
Exploitation ObservedEmpirical Security detected in-the-wild exploitation of Orkes Conductor on August 21, 2026.
Show sources
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — thehackernews.com — 19.09.2026 11:18
-
19.09.2026 11:18 1 articles · 2h ago
Fortinet blocks a surge of CVE-2026-58138 attack attempts
Campaign Scope UpdateBy September 9, 2026, Fortinet had blocked 1,290 attack attempts within 24 hours and nearly 7,000 attempts between September 2 and 9, 2026, with most activity originating from Germany, Hong Kong, Indonesia, the U.A.E., and India.
Show sources
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — thehackernews.com — 19.09.2026 11:18
-
19.09.2026 11:18 2 articles · 2h ago
Fortinet warns of active CVE-2026-58138 exploitation in Orkes Conductor
Initial DisclosureFortinet warned that attackers are actively targeting Orkes Conductor servers susceptible to CVE-2026-58138 by submitting crafted workflow definitions with JavaScript or Python expressions to the workflow API before authentication, and it advised upgrading to Conductor 3.30.2 or later or restricting external API access.
Show sources
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — thehackernews.com — 19.09.2026 11:18
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild — thehackernews.com — 19.09.2026 11:18