Most security inventories never list the workflow engine. Attackers found it anyway.
On September 18 SecurityWeek reported active exploitation of CVE-2026-58138 in Orkes Conductor (conductor-oss) — the open-source microservice / workflow / AI-agent orchestration framework Netflix originally open-sourced. CVSS: 9.8. The bug is unauthenticated remote code execution through inline workflow definitions submitted to the workflow API. Empirical Security’s advisory description: Orkes Conductor versions 3.21.21 before 3.30.2 let attackers execute arbitrary OS commands by submitting malicious JavaScript or Python expressions in INLINE, LAMBDA, DO_WHILE, and SWITCH tasks before authentication.
Mechanism, per Empirical: those task types evaluate user-supplied expressions on a GraalVM context configured with HostAccess.ALL (or allowAllAccess(true) for Python). That turns the sandbox off. From the script object, reflection reaches java.lang.Runtime / ProcessBuilder and runs OS commands as the Conductor process — often root in the default container image. The open-source server enforces no authentication by default and leaves the workflow API open. One unauthenticated POST can register a hostile workflow and start it.
Timeline that matters for operators: fixed in 3.30.2 (June 2026 release notes described restricting GraalVM JavaScript further; CVE published June 30). Public PoC in early August; Exploit-DB entry exists. Empirical telemetry saw in-the-wild activity as recent as August 21. SecurityWeek cites Fortinet blocking roughly 1,300 exploitation attempts between September 8 and 9, with a Fortinet outbreak alert this week. FortiGuard’s threat-signal report (released Sep 9, 2026) states IPS blocked 1,290 attempts in the prior 24 hours (132% day-over-day increase) and 6,696 over seven days (+17% WoW), with highest volumes from Germany, Hong Kong, Indonesia, UAE, and India. Those are blocked-attempt telemetry figures — not a confirmed compromise census. Victim / successful-intrusion count: Undisclosed.
Mitigation, aligned across SecurityWeek, FortiGuard, and Empirical: upgrade to Conductor 3.30.2 or later (do not stop at 3.30.0/3.30.1 — Empirical says those shipped only a partial blocklist). Restrict external access to workflow API endpoints; put instances behind a firewall / reverse-proxy auth; do not expose vulnerable Conductor directly to the internet; hunt suspicious workflow submissions and unexpected child processes from the Conductor JVM. Empirical notes: as of its write-up there was no credentialed Tenable/Qualys plugin, so a clean scanner report does not prove absence — hunt by UI title “Conductor UI,” default port 8080, Swagger, and conductoross/conductor images. Not listed on CISA KEV at last check of Empirical’s page — treat that as absence of a federal clock, not absence of risk.
Reach claim: Empirical cites Orkes saying Conductor runs inside more than 3,000 enterprises (LinkedIn, Twilio, Quest Diagnostics named by the vendor). That is an Orkes commercial claim, not an independent census. The discovery gap is the story — OSS installs that never appear on anyone’s CMDB are still internet-scannable.
POV: Orchestration is the new control plane. Own the workflow engine and you own every system its tasks already reach — including AI-agent graphs bolted onto the same Conductor. A CVSS 9.8 unauth RCE with default-open APIs and FortiGuard outbreak telemetry is not “another OSS bug.” It is a question about whether your inventory even knows Conductor is running. Patch ≥3.30.2. Firewall the workflow API. Count of successful breaches stays Undisclosed. Sources: SecurityWeek Sep 18, FortiGuard threat signal / outbreak alert Sep 9, and Empirical Sep 2026 CVE-of-the-month.
Underwrite sheet — sourced only: CVE-2026-58138; CVSS 9.8; Orkes Conductor / conductor-oss; unauth RCE via INLINE/LAMBDA/DO_WHILE/SWITCH GraalVM HostAccess.ALL (Empirical / SecurityWeek); versions 3.21.21 before 3.30.2; default OSS no auth; often root; fixed 3.30.2 Jun; PoC early Aug / Exploit-DB; Empirical wild Aug 21; Fortinet ~1,300 blocks Sep 8–9 (SecurityWeek); FortiGuard 1,290/24h + 6,696/7d + outbreak Sep 9; not on CISA KEV (Empirical); Orkes >3,000 enterprises claim (vendor via Empirical); victim count Undisclosed. The workflow plane is open until you close it.
