
CVE-2026-58138 is a CVSS 9.8 unauthenticated remote code execution vulnerability affecting Orkes Conductor, the workflow orchestration platform increasingly used in enterprise and cloud-native environments. Fortinet has confirmed the vulnerability is being actively exploited in the wild. Affected versions run from 3.21.21 up to, but not including, 3.30.2.
The critical detail here is the pre-authentication element. An attacker does not need credentials, a phishing foothold, or any prior knowledge of the environment to achieve code execution. That collapses the usual attack chain considerably and puts any internet-exposed or internally accessible Conductor instance at serious risk.
If your organisation uses Orkes Conductor, treat this as an immediate priority. Confirm your version, apply the patch to 3.30.2 or later, and review whether the service is exposed beyond the access boundary it actually needs. Workflow orchestration platforms often hold privileged connections to downstream services, which makes the blast radius of a successful exploit considerably larger than the initial entry point.