The record
Written from the 1 report below. Nothing here is unsourced.
- Orkes Conductor versions 3.21.21 through 3.30.1 are vulnerable to a remote code execution flaw that allows attackers to run arbitrary OS commands by submitting malicious workflow definitions.
- The vulnerability stems from insecure configurations in GraalVM evaluators, which can be manipulated to bypass intended scripting limitations.
- Cybersecurity firms report an increase in active exploitation attempts globally since early September 2026.
What to watch next
- Ongoing monitoring for suspicious workflow submissions and unauthorized command execution on Conductor instances.
- Continued analysis of exploit attempts originating from various global regions.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Fortinet
1 quote · 1 outlet
“Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process”
In the article
…it has observed attackers actively targeting Orkes Conductor servers susceptible to CVE-2026-58138 by submitting crafted workflow definitions containing JavaScript or Python expressions to the Conductor workflow API. " Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process ," Fortinet said. As of September 9, 2026, the company said it had blocked 1,290 attack attempts within a span of 24 hours, representing a 132% increase in daily activity. Nearly 7,000 attempts were blocked between…
Coverage1
All filed from India
Named Germany · Hong Kong SAR China · Indonesia · United Arab Emirates · India · France · United States · Orkes Conductor · Empirical Security · Fortinet · National Vulnerability Database · Previdian
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
