Back to all news
Security

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

The Hacker News·September 19, 2026·1 min read
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability in Orkes Conductor, CVE-2026-58138, is being actively exploited in the wild, according to Fortinet. The flaw, with CVSS scores of 9.8 and 9.3, allows unauthenticated remote code execution. Affected versions include Orkes Conductor 3.21.21 before 3.30.2, enabling remote attackers to compromise systems without authentication.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store