Disclosure summary
What is the Vulnerability? Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
FortiGuard Labs | FortiGuard Center - Threat Signal Report · RSS-d05db4de73c00411657291ea0c1a58618eb
Open original source · Updated Sep 10, 2026
Orkes Conductor Evaluator Remote Code Execution
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- fortiguard.fortinet.com — Publisher advisory
PUBLISHED 2026-09-10T01:13:01-04:00
MODIFIED 2026-09-10T01:13:01-04:00
INGESTED 2026-10-08T12:10:20-04:00