• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / Unauthenticated RCE in Orkes Conductor under active attack

Unauthenticated RCE in Orkes Conductor under active attack

byLotfi Ben Taleb
September 19, 2026
in Security
Reading Time: 3 mins read
Blurred dark computer monitor showing lines of colorful JavaScript source code
Share on Facebook
Share on Twitter

Orkes Conductor has an unauthenticated remote code execution vulnerability, tracked as CVE-2026-58138, and it is already being exploited. The Orkes Conductor vulnerability lets an attacker submit an inline workflow definition and get code running on the server without logging in first, which is about as severe as a pre-auth bug gets. It carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, and affects Orkes Conductor from version 3.21.21 up to, but not including, 3.30.2. The Hacker News, citing Fortinet, reports that the flaw is being actively exploited in the wild.

What the Orkes Conductor vulnerability lets an attacker do

The bug sits in how Conductor processes inline workflow definitions submitted to the platform. Conductor is a workflow orchestration engine used to coordinate microservice tasks, so a compromised instance typically has broad network reach into whatever it’s coordinating. An unauthenticated attacker who can reach the API doesn’t need a valid session or credentials, just a crafted workflow submission, to get the server to execute their code. A 9.8 out of 10 on CVSS v3.1 is about as close to a full house as the scoring rubric gets: network-reachable, no privileges required, no user interaction needed. That makes this a full remote takeover rather than a data-exposure bug: whoever controls the workflow engine controls every task it’s allowed to trigger downstream.

The fix is a version upgrade, not a configuration workaround. Operators running an affected build should:

  • Check the running version against the 3.21.21 to 3.30.2 range
  • Upgrade to 3.30.2 or later
  • Review logs for workflow submissions that don’t match known automation, since exploitation is already under way

Why Orkes Conductor isn’t on CISA’s exploited list yet

CISA’s Known Exploited Vulnerabilities Catalog update on 18 September 2026 wasn’t about Orkes Conductor. It added CVE-2025-39682, a Linux kernel flaw, citing evidence of active exploitation as required under Binding Operational Directive 26-04, which sets remediation deadlines for federal agencies once a vulnerability that grants total control of an asset lands on the catalogue. BOD 26-04 also requires agencies to check whether a system was already compromised before a patch was applied, a reasonable caution for any flaw that’s being exploited ahead of widespread patching. The directive itself only binds federal civilian agencies, but CISA has said it wants all organisations to prioritise remediation using the same catalogue.

Orkes Conductor’s pre-auth RCE fits the profile the directive targets, but as of that advisory CVE-2026-58138 hadn’t been added, despite the exploitation Fortinet reported.

We’ve tracked this gap before. In August, CISA ordered federal agencies to patch an actively exploited flaw in Ray within three days of its KEV listing. That case showed how fast the clock starts once a vulnerability is catalogued. Orkes Conductor’s flaw hasn’t reached that point, so for now the deadline is whatever an operator sets after reading the vendor advisory, not a federal one.

Watch for whether CVE-2026-58138 lands on the KEV catalogue next; if it does, expect a fixed deadline in the same short-window style as the Ray case. Until then, anyone running Orkes Conductor should treat the 3.30.2 release itself as the deadline, since active exploitation doesn’t wait for a catalogue listing before it starts counting against you.

Tags: vulnerability
Previous Post

Sapphire preps a Soulslike-themed Nitro+ RX 9070 XT

Next Post

iPhone 18 Pro Max review begins as bigger battery forces a fix

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rows of blue-lit server hard drive caddies in a data center rack
Security

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

September 27, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

September 28, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Four iPhones laid flat for comparison: dark blue, white with lavender screen, sage green, and green

iPhone 18 Pro Max review begins as bigger battery forces a fix

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply