← All briefs
Brief·2 sources19 Sept 2026

CVE-2026-58138 Actively Exploited In Orkes Conductor RCE Attacks

zero-day-exploitvulnerability-disclosurepatch-managementinitial-access

Summary

A critical unauthenticated remote code execution vulnerability tracked as CVE-2026-58138 in the Orkes Conductor workflow orchestration platform is actively exploited in the wild, with confirmation from Fortinet. The flaw carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, placing it among the highest-severity vulnerability classes. Affected versions span Orkes Conductor 3.21.21 through 3.30.1, with version 3.30.2 containing the patch.

Attackers are exploiting the vulnerability via inline workflow definitions, a mechanism that allows arbitrary code execution without any prior authentication. The absence of an authentication requirement means any network-accessible instance of Orkes Conductor is potentially reachable by a threat actor with no credentials, dramatically lowering the barrier to initial exploitation. Organisations running exposed or internet-facing deployments face the highest risk.

With active exploitation confirmed, remediation is time-critical. Security teams should prioritise patching to version 3.30.2 immediately and audit exposed instances for signs of compromise, particularly looking for unusual workflow execution activity or unexpected outbound connections.

Timeline

  1. 19 September 2026
    Fortinet confirms in-the-wild exploitation; The Hacker News reports
    Fortinet publicly confirmed active exploitation of CVE-2026-58138 in the wild. The Hacker News covered the critical pre-authentication RCE and the availability of a patch in Orkes Conductor 3.30.2.
  2. 18 September 2026
    SecurityWeek reports active exploitation of CVE-2026-58138
    SecurityWeek published details confirming CVE-2026-58138 is being exploited in attacks, describing the inline workflow definition attack vector.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.