Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Élevé · The Hacker News ·
Exploité
Ce qui s'est passé
Unauthenticated RCE (CVE-2026-58138, CVSS 9.8) in Orkes Conductor before 3.30.2 is actively exploited; any org running the workflow platform is at risk.
À faire maintenant
Patch Orkes Conductor to 3.30.2 or later immediately. If patching is delayed, block internet access to the service, restrict to trusted IPs, and hunt for signs of compromise. Verify with vendor advisory.
Références CVE
- CVE-2026-58138
Source originale
Analyse assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.