Fortinet reports active in-the-wild exploitation of CVE-2026-58138 (CVSS 3.1 9.8, CVSS 4.0 9.3), an unauthenticated remote code execution flaw in Orkes Conductor, the workflow orchestration platform. Affected versions are 3.21.21 through before 3.30.2: attackers submit inline workflow definitions containing malicious JavaScript or Python expressions to the Conductor workflow API prior to authentication, and because the GraalVM evaluators can be configured with unrestricted host access (HostAccess.ALL / allowAllAccess(true)) across the INLINE, LAMBDA, DO_WHILE and SWITCH task types, they can invoke arbitrary system commands through Java reflection or direct subprocess calls at the privilege of the Conductor process. Fortinet says it blocked 1,290 attack attempts in 24 hours as of 9 September — a 132 per cent increase in daily activity — and nearly 7,000 attempts between 2 and 9 September, with the majority of activity originating from Germany, Hong Kong, Indonesia, the UAE and India. Previdian recorded three exploitation attempts against its honeypots from two IP addresses in France and the US, and Empirical Security detected exploitation as recently as 21 August. Organisations should upgrade to 3.30.2 or later; where that is not immediately possible, Fortinet's interim guidance is to restrict external access to Conductor workflow API endpoints, place instances behind network access controls, and monitor for suspicious workflow submissions and unexpected command execution.
| Attribute | Detail |
|---|---|
| **Sector | Global (Macro) |
| **Date | 2026-09-20 |
| **Source | The Hacker News |
| **Reliability | Tier 2 |
| **CVEs | CVE-2026-58138 |