Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

Élevé · The Hacker News ·

Exploité

Ce qui s'est passé

Unauthenticated RCE (CVE-2026-58138, CVSS 9.8) in Orkes Conductor before 3.30.2 is actively exploited; any org running the workflow platform is at risk.

À faire maintenant

Patch Orkes Conductor to 3.30.2 or later immediately. If patching is delayed, block internet access to the service, restrict to trusted IPs, and hunt for signs of compromise. Verify with vendor advisory.

Références CVE

  • CVE-2026-58138

Source originale

The Hacker News

Analyse assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber