ZeroHour
Country

U.A.E.

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Unauthenticated RCE CVE-2026-58138 in Orkes Conductor is actively exploited; Fortinet blocked ~7,000 attacks; patch to 3.30.2.

Fortinet reports active in-the-wild exploitation of CVE-2026-58138 (CVSS v3.1 9.8), an unauthenticated remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Attackers submit inline workflow definitions with malicious JavaScript or Python expressions to the workflow API, escaping unsandboxed GraalVM evaluators configured with HostAccess.ALL to run arbitrary OS commands. Fortinet blocked 1,290 attempts in 24 hours as of September 9, 2026, and nearly 7,000 between September 2-9, with most activity from Germany, Hong Kong, Indonesia, the U.A.E., and India. Previdian and Empirical Security also observed exploitation since July 24, 2026.

The Hacker News · 18h agoExploit / PoC in the wild 2 sourcesCVE-2026-581381· 1 read

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Microsoft warns of Teams IT-impersonation intrusions deploying Node.js implants; Spring Ring vishing hit 150+ employees across 10 companies; The Gentlemen ransomware claims 683 victims.

Microsoft warned of a human-operated campaign abusing Teams external collaboration to impersonate IT help desk staff, deploy malicious MSI packages staging Node.js runtimes and obfuscated JavaScript implants, then pivot to domain controllers over WinRM. Unit 42 documented the Spring Ring vishing operation targeting over 150 employees across at least 10 companies using 26 attacker identities, including an NTLM relay variant against domain controllers. Sophos reported The Gentlemen ransomware (Gold Sherwood) reached 683 total victims by end of July 2026, adding 169 in July, with a playbook using BYOVD-based EDR killers and backup tampering. Group-IB found the Outsider phishing-as-a-service platform created 700+ new phishing pages within a month despite law enforcement takedowns.

The Hacker News · 16d agoThreat actor in the wild1

Related CVEs

  • Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS comma
    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.