CVE-2026-58138Active Exploitation

CRITICALCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 16 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 43 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 61 mentions across 12 observed days

What's happening

  • Active exploitation reported across 43 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 34 signals
  • Technical details provided in 46 signals
  • Peaked 6d ago at 16 mentions (2026-09-19); latest day: 1
  • 61 total mentions across 12 days

Deep dive

Activity timeline61 mentions / 12d
0481216Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-16: 1Mentions · 2026-07-27: 2Mentions · 2026-09-18: 9Mentions · 2026-09-19: 16Mentions · 2026-09-20: 13Mentions · 2026-09-21: 8Mentions · 2026-09-22: 5Mentions · 2026-09-23: 2Mentions · 2026-09-27: 2Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-06-30: 1PoC Mentioned / Linked · 2026-07-27: 1PoC Mentioned / Linked · 2026-09-18: 3PoC Mentioned / Linked · 2026-09-19: 1PoC Mentioned / Linked · 2026-09-20: 3Exploit Tool / Code · 2026-09-19: 1Exploit Tool / Code · 2026-09-20: 2Exploit Tool / Code · 2026-09-22: 1Active Exploitation · 2026-07-27: 2Active Exploitation · 2026-09-18: 8Active Exploitation · 2026-09-19: 15Active Exploitation · 2026-09-20: 10Active Exploitation · 2026-09-21: 5Active Exploitation · 2026-09-22: 3Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-09-18: 7Patch / Workaround · 2026-09-19: 9Patch / Workaround · 2026-09-20: 11Patch / Workaround · 2026-09-21: 5Patch / Workaround · 2026-09-22: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-27: 2Technical Details · 2026-09-18: 9Technical Details · 2026-09-19: 15Technical Details · 2026-09-20: 12Technical Details · 2026-09-21: 5Technical Details · 2026-09-22: 106-3007-0107-1607-2709-1809-1909-2009-2109-2209-2309-2709-30
Signal classification5 categories
Active Exploitation
4382.7%
Patch
59.6%
PoC
23.8%
Disclosure
11.9%
General
11.9%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-301
PoC1
2026-07-011
Disclosure1
2026-07-161
Patch1
2026-07-272
Active Exploitation2
2026-09-189
Active Exploitation8Patch1
2026-09-1916
Active Exploitation15PoC1
2026-09-2013
Active Exploitation10General1Patch2
2026-09-218
Active Exploitation5Patch1
2026-09-225
Active Exploitation3
Full discourse20 posts
  • OpenTaint@seqradev
    Patch

    We're sharing our deep dive into CVE-2026-58138, a critical unauthenticated RCE in Conductor with a CVSS score of 9.8, where a single POST request can lead to arbitrary OS command execution on the server. The post walks through how the vulnerability reaches GraalJS and GraalPy evaluators, how we reproduced it across multiple workflow task types, and how OpenTaint traced the complete path from HTTP input to code execution. If you run Conductor, upgrade to version 3.30.2 or later, and take a look at the full technical analysis: https://opentaint.org/blog/conductor-rce-cve-2026-58138/

    Post summary

    The post details CVE‑2026‑58138, a critical unauthenticated RCE in Conductor, and recommends users upgrade to version 3.30.2 or later to remediate the issue.

    371819411.7K
    21 followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Explotan vulnerabilidad crítica de RCE sin autenticación en la plataforma Orkes Conductor Fortinet advirtió sobre una vulnerabilidad crítica (CVE-2026-58138) en Orkes Conductor https://blog.elhacker.net/2026/09/explotan-vulnerabilidad-critica-de-rce.html

    Post summary

    The tweet reports that CVE-2026-58138, a critical unauthenticated RCE in Orkes Conductor, is being actively exploited, with Fortinet warning about the issue.

    0201434.5K
    142.2K followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    🚨 Exploitation observed. Not yet in CISA KEV at time of posting. KEVIntel sensors captured an unauthenticated RCE attempt targeting CVE-2026-58138 in Orkes Conductor. • CVSS 9.3 • Public PoC available • Affects 3.21.21 to <3.30.2 Prioritise exposed Conductor systems. https://t.co/cKh4WYvXuz

    Post summary

    CVE-2026-58138 in Orkes Conductor is being actively exploited in the wild; a public PoC exists and vulnerable versions range from 3.21.21 to <3.30.2.

    111501.7K
    61 followersView on X
  • DrMashari@GMashari
    Active Exploitation

    📌 ثغرة تنفيذ عن بعد قبل المصادقة في منصة Orkes Conductor لتدفق العمل تُستغل في البرية 🛡️ الفئة: ثغرة 📝 الملخص: تم اكتشاف ثغرة أمنية حرجة في منصة Orkes Conductor لتدفق العمل، وهي قابلة للاستغلال في البرية وفقًا لتقارير Fortinet. هذه الثغرة، المُعرفَة بـ CVE-2026-58138، تتيح تنفيذًا عن بعد دون مصادقة، مما يمكّن المهاجمين من تشغيل أكواد خبيثة على الخوادم المستهدفة. النسخ من Orkes Conductor 3.21.21 قبل 3.30.2 تتأثر بهذه الثغرة. — يُنصح بـ تحديث النسخة إلى 3.30.2 على الأقل لتجنب الاستغلال. 🗓️ تاريخ النشر: 19/09/2026 🔗 للمزيد: https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html

    Post summary

    The post reports CVE-2026-58138 as a critical pre-auth RCE in Orkes Conductor exploited in the wild and recommends updating to version 3.30.2.

    21030435
    9.5K followersView on X
  • Ryx@PadhiyarRushi
    Active Exploitation

    Orkes Conductor unauth RCE under active exploitation. CVE-2026-58138 (CVSS 9.8): when access is set too permissively, INLINE / LAMBDA / DO_WHILE / SWITCH tasks can be abused for arbitrary OS commands via reflection or subprocess. Fortinet reported thousands of blocked attempts in early September. https://cyberrecaps.com/news/cybersecurity-news-september-20-2026 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #RCE #CloudSecurity

    Post summary

    The post reports that CVE-2026-58138 is under active exploitation, with Fortinet blocking thousands of attempts, and provides technical details of the vulnerability.

    10031405
    939 followersView on X
  • FortiGuard Labs@FortiGuardLabs

    WORKFLOW STATUS: APPROVED ✅ AUTHENTICATION: NOT REQUIRED 🚫 RESULT: OS COMMAND EXECUTION 🚨 That is the problem with CVE-2026-58138. #FortiGuardLabs is seeing active attack attempts against vulnerable Orkes Conductor deployments, where malicious workflow definitions can escape the intended scripting environment and execute commands on the underlying server. 🔗 Get the technical analysis: https://ow.ly/5SM150ZPb1l

    11030766
    40.6K followersView on X
  • YBE@Lumideezy
    Active Exploitation

    Critical pre-auth RCE in Orkes Conductor (CVE-2026-58138, CVSS 9.8) is being actively exploited. Update to 3.30.2 or later immediately if you run workflow platforms. Isolation and least privilege remain essential. #CyberSecurity

    Post summary

    The text reports active exploitation of a critical pre-auth RCE in Orkes Conductor (CVE-2026-58138, CVSS 9.8) and urges immediate update to version 3.30.2 or later.

    0104089
    4.8K followersView on X
  • ShikataGaNai@0x00Sector

    Autonomous local AI agents took CVE-2026-58138 into an isolated @orkesio Conductor lab. They turned a workflow into root inside the victim container, verified the 3.30.2 fix, then built detections for the success path the server barely logged. Case 005 👇 https://t.co/GCKqB6h3cZ

    2002062
    66 followersView on X
  • ShikataGaNai@0x00Sector

    @orkesio Full paper, PoC, evidence, A/B fix verification, 8 Suricata signatures, 2 Sigma rules, 5 YARA rules and both films: https://github.com/MangelZabalaDevelop/autonomous-research-lab/tree/main/CVE-2026-58138

    1002052
    66 followersView on X
  • C2 Hunters Research@C2HuntersLabs
    Active Exploitation

    We're seeing attackers scan for and exploit CVE-2026-58138, a critical flaw in Orkes/OSS Conductor that needs no login to abuse. One tool we analysed scans hundreds of servers, breaks in as root, then hunts for passwords, internal network layout and running processes.

    Post summary

    Attackers are actively exploiting CVE-2026-58138, a critical unauthenticated flaw in Orkes/OSS Conductor, using a custom scanning/exploitation tool that gains root access and enumerates internal resources.

    1100080
    15 followersView on X
  • Anthony Bahn@HoustonIntrove1
    Active Exploitation

    Unpatched Orkes Conductor is pre-auth RCE. CVE-2026-58138 turns a workflow definition into OS commands as the Conductor process, often root, with wild use since August. Ship 3.30.2, put auth on 8080, and do not wait for CISA KEV. https://www.anthonybahn.com/news/orkes-conductor-cve-2026-58138-unauthenticated-graalvm-evaluator-rce/

    Post summary

    The text reports active in-the-wild exploitation of CVE-2026-58138 (pre-auth RCE in Orkes Conductor) since August, names the patched version 3.30.2 and a workaround (auth on 8080), and urges action before CISA KEV listing.

    1001077
    37 followersView on X
  • كاسبر سكاي@KasperskyDev
    Active Exploitation

    🔴 ثغرة تنفيذ كود عن بُعد بلا مصادقة في منصة أوركيس كوندكتور تُستغل فعلياً. المعرّف : CVE-2026-58138 درجة الخطورة : 9.8 (CVSS) - Critical الحالة : Actively exploited الحل : Conductor 3.30.2 الرابط :

    Post summary

    The alert reports CVE-2026-58138, a critical unauthenticated RCE in Orkes Conductor (CVSS 9.8), confirming active exploitation in the wild and identifying version 3.30.2 as the patched release.

    11000232
    39.9K followersView on X
  • sunil kumawat@Sunil_kumawat17
    Patch

    @GMashari CVE-2026-58138 is especially dangerous because the attack path is an unauthenticated workflow submission, not an exotic parser. Upgrade Conductor to 3.30.2+ and keep workflow APIs behind an authenticated, non-public boundary.

    Post summary

    The tweet warns about CVE-2026-58138 in Conductor, outlining the technical nature of the exploit as an unauthenticated workflow submission, and directs administrators to upgrade to version 3.30.2+ and restrict API access.

    0002042
    23 followersView on X
  • CloudSecurityAlliance@cloudsa
    Active Exploitation

    CISO Daily Briefing: Orkes Conductor RCE (CVE-2026-58138, CVSS 9.8) — 7K exploit attempts/week, patch now; CISA's 72hr KEV clock on 3 Linux kernel bugs expires tomorrow. An ex-employee's still-active GitHub token (stolen via the TanStack npm attack) let attackers clone 170 CrowdSec repos over 4 months — MFA can't stop a valid token. CISA's first honeytoken/decoy guidance drops as Google, OpenAI, and UK AISI all disclose unsanctioned agent actions this week. https://labs.cloudsecurityalliance.org/ciso-daily-briefing-september-20-2026/

    Post summary

    The briefing reports active exploitation of Orkes Conductor RCE (CVE-2026-58138) with thousands of weekly attempts and CISA KEV Linux kernel bugs, urging immediate patching.

    00020562
    18.9K followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/09/20 🚨 1. Cisco ISE CVSS 10 auth bypass under active attack CVE-2026-76460 lets unauthenticated attackers bypass the management interface on Identity Services Engine and ISE-PIC. Cisco confirmed exploitation; CISA added it to KEV with a short remediation window. Patch to the fixed releases immediately. 2. CISA flags three Linux kernel flaws as actively exploited CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964 went into the KEV catalog. Federal agencies must remediate by September 21. Red Hat confirmed public exploits exist for at least one of them. 3. Orkes Conductor pre-auth RCE exploited in the wild CVE-2026-58138 (CVSS 9.8) allows unauthenticated remote code execution via malicious workflow definitions. Fortinet blocked nearly 7,000 attempts in one week. Upgrade to 3.30.2 or later. 4. Gyazo breach exposes 23.6 million user records Attackers exploited an image-upload server flaw on September 11 and stole account data plus 490 million image metadata records. Password hashes, emails and some tokens are among the exposed items. 5. ShinyHunters defaces Clop ransomware leak site The group claimed full access after an unauthenticated Grav CMS upload, replaced the Tor site with its own branding and said it plans to extort the rival operation. #Cybersecurity #CISA #NIST

    Post summary

    The bulletin reports multiple CVEs under active exploitation, including CISA KEV listings, public exploits for Linux kernel flaws, and specific remediation actions such as patching Cisco ISE and upgrading Orkes Conductor.

    20000136
    94 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Orkes Conductor Workflow API Pre-Auth Script RCE (CVE-2026-58138) Orkes Conductor’s workflow API endpoint accepts unauthenticated inline workflow definitions that embed malicious JavaScript/Python expressions. When GraalVM evaluators run with HostAccess.ALL or allowAllAccess(true), INLINE/LAMBDA/DO_WHILE/SWITCH tasks can reach OS command execution via reflection/subprocess, leading to full RCE. 👉Affected: Orkes Conductor (conductor) >= 3.21.21 < 3.30.2 | Upgrade to 3.30.2

    Post summary

    A critical RCE vulnerability (CVE-2026-58138) in Orkes Conductor's workflow API allows unauthenticated code execution via malicious inline workflow tasks. Users should upgrade to version 3.30.2 or later to mitigate the issue.

    10010122
    307 followersView on X
  • Anurag Verma@anurag_629
    Active Exploitation

    a single request with no auth can hand an attacker root on your workflow engine. CVE-2026-58138: submit a malicious @orkesio Conductor workflow with an inline JS expression, escape the sandbox through Java interop, run OS commands. CVSS 9.8. FortiGuard blocked nearly 7,000 exploitation attempts between Sept 2-9. Patched in 3.30.2 back in June, still getting hit today. if you're on 3.21.21 through 3.30.1, patch now: https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html

    Post summary

    This disclosure highlights CVE-2026-58138, an unauthenticated RCE in Orkes Conductor, noting FortiGuard detected nearly 7,000 exploitation attempts and confirming the flaw was patched in version 3.30.2, with active attacks still ongoing against older versions.

    0002065
    316 followersView on X
  • TwitGri@TwitGri
    Active Exploitation

    ⚠️ Cyber : Orkes Conductor CVE-2026-58138 (RCE sans auth) est activement exploitée. Fortinet a bloqué ~1 300 tentatives les 8-9 sept. Si vous utilisez Conductor &lt;3.30.2 : mettez à jour et n’exposez plus l’API workflow à Internet. #Cyber #CVE

    Post summary

    The tweet reports that CVE-2026-58138 in Orkes Conductor is being actively exploited, with Fortinet blocking numerous attempts, and urges users to update to version 3.30.2 or later and restrict API exposure.

    1001051
    36 followersView on X
  • SOCMinute@SOCMinute
    Active Exploitation

    Critical unauthenticated RCE CVE-2026-58138 is actively exploited in Orkes Conductor versions before 3.30.2. Immediate patching essential to prevent full system compromise. #OrkesConductor #CVE2026 #RCE #PatchManagement #SOCMinute https://t.co/hpmtbiFP1e

    Post summary

    The tweet reports that CVE-2026-58138, a critical unauthenticated RCE affecting Orkes Conductor versions before 3.30.2, is being actively exploited and stresses the need for immediate patching.

    0001040
    14 followersView on X
  • SynScanNet@SynScanNet
    Active Exploitation

    CVE-2026-58138, CVSS 9.8. Orkes Conductor's workflow API runs attacker-supplied JavaScript or Python expressions as OS commands, no login needed. Fortinet blocked 1,290 attempts in one day. Fix shipped in June (3.30.2). Public PoC and a Nuclei template exist. https://t.co/oUKrrU4MUW

    Post summary

    The text details CVE-2026-58138, a critical vulnerability in Orkes Conductor allowing unauthenticated OS command execution, which is being actively exploited in the wild with thousands of attempts blocked, while a fix and public PoC/Nuclei template are available.

    1000061
    5 followersView on X

Explore more