Critical Orkes Conductor Vulnerability Exploited in Attacks

A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month.

Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents.

Tracked as CVE-2026-58138 (CVSS score of 9.8), the critical bug is described as a remote code execution issue exploitable via inline workflow definitions submitted to the workflow API endpoint.

Attackers can include malicious JavaScript or Python expressions in the definitions to invoke arbitrary system commands. The flaw affects how Conductor runs scripts inside a workflow.

“An INLINE task (and LAMBDA, DO_WHILE, and SWITCH tasks) evaluates a user-supplied JavaScript or Python expression, and Conductor builds that evaluator on a GraalVM context configured with HostAccess.ALL,” Empirical Security explains.

This configuration disables the sandbox, and the attacker-supplied code reflects into the Java runtime and executes OS commands as the Conductor process, which often runs with root privileges.

Advertisement. Scroll to continue reading.

“No login stands in the way, because the open-source server enforces no authentication by default and leaves its workflow API open. A single unauthenticated POST registers a workflow with a hostile INLINE task and starts it,” Empirical notes.

CVE-2026-58138 was patched in June in Orkes Conductor version 3.30.2. Proof-of-concept (PoC) code targeting it was published in early August, and exploitation started shortly after.

Empirical identified in-the-wild attacks on August 21, and Fortinet blocked roughly 1,300 exploitation attempts between September 8 and 9. This week, Fortinet released an outbreak alert on the vulnerability’s ongoing exploitation.

In addition to updating to Conductor 3.30.2 or later, organizations should restrict external access to Conductor’s workflow API endpoints and ensure Conductor deployments are behind a firewall and that their services are not directly exposed to the internet.

They should also monitor their instances for suspicious workflow submissions and unauthorized command execution, and review systems running vulnerable versions for signs of intrusion.

Related: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Related: ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Related: Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/




Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.

The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.

https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/




CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.

https://www.securityweek.com/cisa-retires-weekly-vulnerability-bulletin-in-risk-based-pivot/




ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.

The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.

https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/




Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.

The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/




Pixel Modem Zero-Day Exploited in Targeted Attacks

Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.

The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.

https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks/




Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.

The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.

https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/




Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Oracle on Tuesday announced the release of 673 new security patches as part of its September 2026 Critical Security Patch Update (CSPU).

The security updates appear to resolve more than 800 vulnerabilities: there are 672 unique CVEs in the 17 risk matrices included in the September 2026 CSPU advisory, but Oracle also notes that more than 130 additional CVEs have been resolved with the patches for other flaws.

More than 100 of the newly addressed security defects are critical-severity flaws, and over 240 are remotely exploitable without authentication.

Oracle E-Business Suite received 159 security patches, the largest batch of the CSPU. 19 of the vulnerabilities can be exploited remotely without authentication.

Fusion Middleware followed closely, receiving 153 patches, including fixes for 78 unauthenticated, remotely exploitable flaws. Hyperion was third, with 102 patches (50 remotely exploitable without authentication).

Oracle also rolled out a significant number of patches for Siebel CRM (63), Analytics (50), Communications (31), Commerce (27), Supply Chain (19), Virtualization (19), and PeopleSoft (16).

Advertisement. Scroll to continue reading.

The Communications update stands out, as half of its patches resolve more than 125 additional CVEs.

Other Oracle products that received patches this month include Database Server, Enterprise Manager, Financial Services Applications, Application Testing Suite, Java SE, Autonomous Health Framework, and Utilities Applications.

Oracle makes no mention of any of these vulnerabilities being exploited in the wild, but warns users that threat actors are regularly exploiting flaws in its products, urging customers to apply the updates as soon as possible.

“In some instances, it has been reported that attackers have been successful because targeted customers had failed to apply available Oracle patches. Oracle therefore strongly recommends that customers remain on actively-supported versions and apply security patches without delay,” Oracle notes.

Related: $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

Related: Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

Related: Thai Broadband Provider Hacked via Fortinet Vulnerability

Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/




$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.

The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.

https://www.securityweek.com/1-million-sandbox-challenge-uncovers-linux-kernel-flaws/




Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases 

The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.

The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  appeared first on SecurityWeek.

https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/