Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Google DeepMind launches institute to widen the AGI debate

    September 18, 2026

    Alibaba Qwen Releases Qwen3.8-Omni-Flash: A 1M-Context Omni-Modal Model Built Around Agentic Audio-Video Understanding and Tool Use

    September 18, 2026

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Google DeepMind launches institute to widen the AGI debate
    • Alibaba Qwen Releases Qwen3.8-Omni-Flash: A 1M-Context Omni-Modal Model Built Around Agentic Audio-Video Understanding and Tool Use
    • Critical Orkes Conductor Vulnerability Exploited in Attacks
    • Bitcoin May Have Bottomed at $58K, Analysts Say
    • James Webb reveals Chariklo’s mysterious rings are changing faster than expected
    • California Adopts New Limits to Rein in Dairy Manure Pollution and Its ‘Outsized’ Groundwater Impacts
    • Slowly then all at once: this emboldened Celtic alliance could spell the end of the UK | Simon Jenkins
    • Philippines: At least one dead and multiple injured in shooting at Banga high school
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 18, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month.

    Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents.

    Tracked as CVE-2026-58138 (CVSS score of 9.8), the critical bug is described as a remote code execution issue exploitable via inline workflow definitions submitted to the workflow API endpoint.

    Attackers can include malicious JavaScript or Python expressions in the definitions to invoke arbitrary system commands. The flaw affects how Conductor runs scripts inside a workflow.

    “An INLINE task (and LAMBDA, DO_WHILE, and SWITCH tasks) evaluates a user-supplied JavaScript or Python expression, and Conductor builds that evaluator on a GraalVM context configured with HostAccess.ALL,” Empirical Security explains.

    This configuration disables the sandbox, and the attacker-supplied code reflects into the Java runtime and executes OS commands as the Conductor process, which often runs with root privileges.

    Advertisement. Scroll to continue reading.

    “No login stands in the way, because the open-source server enforces no authentication by default and leaves its workflow API open. A single unauthenticated POST registers a workflow with a hostile INLINE task and starts it,” Empirical notes.

    CVE-2026-58138 was patched in June in Orkes Conductor version 3.30.2. Proof-of-concept (PoC) code targeting it was published in early August, and exploitation started shortly after.

    Empirical identified in-the-wild attacks on August 21, and Fortinet blocked roughly 1,300 exploitation attempts between September 8 and 9. This week, Fortinet released an outbreak alert on the vulnerability’s ongoing exploitation.

    In addition to updating to Conductor 3.30.2 or later, organizations should restrict external access to Conductor’s workflow API endpoints and ensure Conductor deployments are behind a firewall and that their services are not directly exposed to the internet.

    They should also monitor their instances for suspicious workflow submissions and unauthorized command execution, and review systems running vulnerable versions for signs of intrusion.

    Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

    Related: ISC Patches 14 Vulnerabilities in BIND 9 Security Update

    Related: Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

    attacks Conductor critical Exploited Orkes Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft fixes broken copy and paste for Excel 2016 users

    RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

    US takes down NightmareStresser DDoS-for-hire platform

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Google DeepMind launches institute to widen the AGI debate

    September 18, 2026

    Alibaba Qwen Releases Qwen3.8-Omni-Flash: A 1M-Context Omni-Modal Model Built Around Agentic Audio-Video Understanding and Tool Use

    September 18, 2026

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    September 18, 2026

    Bitcoin May Have Bottomed at $58K, Analysts Say

    September 18, 2026
    Latest Posts

    ADNOC, SLB roll out AI-powered tool across over 120 rigs to enhance drilling ops

    August 4, 2026

    Mining threat persists in Raja Ampat, Indonesia’s ‘Amazon of the Seas’

    August 4, 2026

    Smoke Streams Across Eastern Washington

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Google DeepMind launches institute to widen the AGI debate

    September 18, 2026

    Alibaba Qwen Releases Qwen3.8-Omni-Flash: A 1M-Context Omni-Modal Model Built Around Agentic Audio-Video Understanding and Tool Use

    September 18, 2026

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    September 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.