Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Unauthenticated RCE CVE-2026-58138 in Orkes Conductor is actively exploited; Fortinet blocked ~7,000 attacks; patch to 3.30.2.
Fortinet reports active in-the-wild exploitation of CVE-2026-58138 (CVSS v3.1 9.8), an unauthenticated remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Attackers submit inline workflow definitions with malicious JavaScript or Python expressions to the workflow API, escaping unsandboxed GraalVM evaluators configured with HostAccess.ALL to run arbitrary OS commands. Fortinet blocked 1,290 attempts in 24 hours as of September 9, 2026, and nearly 7,000 between September 2-9, with most activity from Germany, Hong Kong, Indonesia, the U.A.E., and India. Previdian and Empirical Security also observed exploitation since July 24, 2026.