<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Workflow-Orchestration on CuraSec</title><link>https://curasec.metacog.co.kr/tags/workflow-orchestration/</link><description>Recent content in Workflow-Orchestration on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 19 Sep 2026 14:22:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/workflow-orchestration/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical Pre-Auth RCE in Orkes Conductor Exploited in the Wild</title><link>https://curasec.metacog.co.kr/insights/2026-09-19-critical-pre-auth-rce-in-orkes-conductor-workflow-platform-e/</link><pubDate>Sat, 19 Sep 2026 14:22:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-19-critical-pre-auth-rce-in-orkes-conductor-workflow-platform-e/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Actively exploited pre-auth RCE with a public PoC on GitHub overrides the low EPSS; patch Orkes Conductor to 3.30.2 or later immediately if running any version before that.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation confirmed by Fortinet means assume-breach posture for any environment running Orkes Conductor — sweep for anomalous process spawns from the Conductor service and pull Fortinet&amp;rsquo;s report for available IOCs to hunt against SIEM data.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Verify whether Orkes Conductor is in your tech stack; if confirmed, escalate to engineering as urgent given active exploitation of a 9.8 CVSS pre-auth RCE — this is not yet a board-level systemic event unless your org is exposed.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-58138 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>