Critical Remote Code Execution Flaw Found in Orkes Conductor, Actively Exploited
A critical unauthenticated remote code execution vulnerability, CVE-2026-58138, has been discovered in Orkes Conductor's GraalVM Script Evaluators and is currently being actively exploited. Rated 9.8 Critical on CVSS 3.1, this flaw allows malicious servers to compromise applications using the official Model Context Protocol Python SDK by stealing OAuth credentials. A fix is available in Conductor v3.30.2.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.