Attackers are actively exploiting a critical vulnerability in the Orkes Conductor workflow platform, according to reporting from multiple outlets. The issue is identified as CVE-2026-58138, which is described as an unauthenticated remote code execution (RCE) flaw. One outlet notes that exploitation can occur through inline workflow definitions.
The Hacker News reports that Fortinet has observed real-world attacks leveraging the vulnerability. It cites severity scores of 9.8 on CVSS v3.1 and 9.3 on CVSS v4, framing the problem as pre-auth due to the lack of authentication required to trigger the RCE. SecurityWeek similarly characterizes the flaw as unauthenticated and remote, emphasizing how attackers use workflow-related input to achieve code execution.
While both sources agree on the exploitability and unauthenticated RCE nature of CVE-2026-58138, they differ mainly in focus: SecurityWeek highlights the specific mechanism involving inline workflow definitions, while The Hacker News emphasizes Fortinet’s assessment and the vulnerability’s CVSS ratings.