Critical Vulnerability Alert: Orkes Conductor Workflow Platform

CISOs must prioritize patching Orkes Conductor immediately to prevent exploitation of CVE-2026-58138.

Bottom line: CISOs must prioritize patching Orkes Conductor immediately to prevent exploitation of CVE-2026-58138.

What's happening: The vulnerability was publicly disclosed by Fortinet on December 1, 2022. Orkes Conductor version 3.21.21 is affected, and attackers have already begun exploiting this vulnerability in the wild. No CVE ID is publicly available for the exploit.

What to do: Security teams should perform a vulnerability scan and patch Orkes Conductor version 3.21.21 as soon as possible. CISOs should also review and update incident response plans to address the exploitation of this critical vulnerability.

Source: The Hacker News