Critical Flaw in Orkes Conductor Being Actively Exploited, Patch Now
A critical security flaw in Orkes Conductor, a workflow automation platform, is being actively exploited by attackers, according to security firm Fortinet. The vulnerability, tracked as CVE-2026-58138, allows attackers to run malicious commands on vulnerable servers without needing to log in first. It works by submitting crafted workflow definitions containing malicious code to the platform's API, exploiting scripting components that were configured with unrestricted system access.
Fortinet reported blocking 1,290 attack attempts in a single 24 hour period in early September 2026, a 132% jump in daily activity, with nearly 7,000 attempts blocked over one week. Attack traffic was traced mainly to Germany, Hong Kong, Indonesia, the U.A.E. and India. Other security researchers, including Previdian and Empirical Security, confirmed separate exploitation attempts dating back to late July 2026, showing the threat has been active for some time before wider attention.
Organisations running affected versions of Orkes Conductor (3.21.21 before 3.30.2) should upgrade immediately to version 3.30.2 or later, which fixes the flaw. Where patching isn't immediately possible, businesses should restrict external access to Conductor's API endpoints, place instances behind network access controls, and monitor for unusual workflow submissions or unexpected command activity.