Critical Unauthenticated Remote Code Execution in Orkes Conductor Workflow Platform Under Active Exploitation
A critical vulnerability designated CVE-2026-58138 in the Orkes Conductor workflow orchestration platform allows unauthenticated remote code execution.…
If Orkes Conductor is deployed in your infrastructure, upgrade immediately to version 3.30.2 or later. Monitor access logs for exploitation attempts. Consider isolating affected systems on high-risk network segments until patching is complete.