OpenTaint[verified]@seqradevPatch
The post details CVE‑2026‑58138, a critical unauthenticated RCE in Conductor, and recommends users upgrade to version 3.30.2 or later to remediate the issue.
Ryx[verified]@PadhiyarRushiActive Exploitation
The post reports that CVE-2026-58138 is under active exploitation, with Fortinet blocking thousands of attempts, and provides technical details of the vulnerability.
YBE[verified]@LumideezyActive Exploitation
The text reports active exploitation of a critical pre-auth RCE in Orkes Conductor (CVE-2026-58138, CVSS 9.8) and urges immediate update to version 3.30.2 or later.
Anthony Bahn[verified]@HoustonIntrove1Active Exploitation
The text reports active in-the-wild exploitation of CVE-2026-58138 (pre-auth RCE in Orkes Conductor) since August, names the patched version 3.30.2 and a workaround (auth on 8080), and urges action before CISA KEV listing.
CloudSecurityAlliance[verified]@cloudsaActive Exploitation
The briefing reports active exploitation of Orkes Conductor RCE (CVE-2026-58138) with thousands of weekly attempts and CISA KEV Linux kernel bugs, urging immediate patching.
Frontiera Tech[verified]@FrontieraTechITActive Exploitation
The bulletin reports multiple CVEs under active exploitation, including CISA KEV listings, public exploits for Linux kernel flaws, and specific remediation actions such as patching Cisco ISE and upgrading Orkes Conductor.
Upwind Security MDR[verified]@UpwindMDRPatch
A critical RCE vulnerability (CVE-2026-58138) in Orkes Conductor's workflow API allows unauthenticated code execution via malicious inline workflow tasks. Users should upgrade to version 3.30.2 or later to mitigate the issue.
Anurag Verma[verified]@anurag_629Active Exploitation
This disclosure highlights CVE-2026-58138, an unauthenticated RCE in Orkes Conductor, noting FortiGuard detected nearly 7,000 exploitation attempts and confirming the flaw was patched in version 3.30.2, with active attacks still ongoing against older versions.