CuraSec

tag: Workflow-Orchestration · 1 items

  • Engineer — Act: Actively exploited pre-auth RCE with a public PoC on GitHub overrides the low EPSS; patch Orkes Conductor to 3.30.2 or later immediately if running any version before that.
  • SOC/IR — Act: Active exploitation confirmed by Fortinet means assume-breach posture for any environment running Orkes Conductor — sweep for anomalous process spawns from the Conductor service and pull Fortinet’s report for available IOCs to hunt against SIEM data.
  • Leader — Plan: Verify whether Orkes Conductor is in your tech stack; if confirmed, escalate to engineering as urgent given active exploitation of a 9.8 CVSS pre-auth RCE — this is not yet a board-level systemic event unless your org is exposed.
  • Signals: CVE-2026-58138 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub