Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    September 20, 2026

    Typesafe AI JEV is a Transformational Unlock for AI Decisions & Classifications and Huge Speed and Cost Savings for AI Software – NextBigFuture.com

    September 20, 2026

    Bose QuietComfort Headphones (2nd Gen) review: great, pricey

    September 20, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Critical Orkes Conductor Vulnerability Exploited in Attacks
    Critical Orkes Conductor Vulnerability Exploited in Attacks
    Cybersecurity

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    The Tech GuyBy The Tech GuySeptember 20, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month.

    Advertisement

    Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents.

    Tracked as CVE-2026-58138 (CVSS score of 9.8), the critical bug is described as a remote code execution issue exploitable via inline workflow definitions submitted to the workflow API endpoint.

    Attackers can include malicious JavaScript or Python expressions in the definitions to invoke arbitrary system commands. The flaw affects how Conductor runs scripts inside a workflow.

    “An INLINE task (and LAMBDA, DO_WHILE, and SWITCH tasks) evaluates a user-supplied JavaScript or Python expression, and Conductor builds that evaluator on a GraalVM context configured with HostAccess.ALL,” Empirical Security explains.

    This configuration disables the sandbox, and the attacker-supplied code reflects into the Java runtime and executes OS commands as the Conductor process, which often runs with root privileges.

    Advertisement. Scroll to continue reading.

    “No login stands in the way, because the open-source server enforces no authentication by default and leaves its workflow API open. A single unauthenticated POST registers a workflow with a hostile INLINE task and starts it,” Empirical notes.

    CVE-2026-58138 was patched in June in Orkes Conductor version 3.30.2. Proof-of-concept (PoC) code targeting it was published in early August, and exploitation started shortly after.

    Empirical identified in-the-wild attacks on August 21, and Fortinet blocked roughly 1,300 exploitation attempts between September 8 and 9. This week, Fortinet released an outbreak alert on the vulnerability’s ongoing exploitation.

    In addition to updating to Conductor 3.30.2 or later, organizations should restrict external access to Conductor’s workflow API endpoints and ensure Conductor deployments are behind a firewall and that their services are not directly exposed to the internet.

    They should also monitor their instances for suspicious workflow submissions and unauthorized command execution, and review systems running vulnerable versions for signs of intrusion.

    Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

    Related: ISC Patches 14 Vulnerabilities in BIND 9 Security Update

    Related: Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    NightmareStresser DDoS Service Disrupted in International Operation

    September 19, 2026

    TigerByte Cyber Emerges From Stealth With $3 Million in Funding

    September 19, 2026

    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    September 19, 2026

    23 Million User Records Compromised in Gyazo Data Breach 

    September 19, 2026

    AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

    September 18, 2026

    In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    September 18, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Critical Orkes Conductor Vulnerability Exploited in Attacks

    September 20, 2026

    Typesafe AI JEV is a Transformational Unlock for AI Decisions & Classifications and Huge Speed and Cost Savings for AI Software – NextBigFuture.com

    September 20, 2026

    Bose QuietComfort Headphones (2nd Gen) review: great, pricey

    September 20, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.