Act
active
Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild
- Engineer — Act: Actively exploited pre-auth RCE with a public PoC on GitHub overrides the low EPSS; patch Orkes Conductor to 3.30.2 or later immediately if running any version before that.
- SOC/IR — Act: Active exploitation confirmed by Fortinet means assume-breach posture for any environment running Orkes Conductor — sweep for anomalous process spawns from the Conductor service and pull Fortinet’s report for available IOCs to hunt against SIEM data.
- Leader — Plan: Verify whether Orkes Conductor is in your tech stack; if confirmed, escalate to engineering as urgent given active exploitation of a 9.8 CVSS pre-auth RCE — this is not yet a board-level systemic event unless your org is exposed.
- Signals: CVE-2026-58138 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.