Orkes Conductor’s unauthenticated RCE is now exploited in the wild, three months after disclosure
On September 19, 2026, Fortinet confirmed active exploitation of CVE-2026-58138, an unauthenticated remote code execution flaw in Orkes Conductor that was published to the NVD on June 30. Upgrade to 3.30.2 and treat any exposed instance as compromised.