Welcome Guest
Username: Password:   September 22 2026, 11:49 AM
1
 

 
Home
About Us
Services
Products
News
Support
Contact Us

 

FortiGuard Labs | FortiGuard Center - Outbreak Alerts

Orkes Conductor Evaluator Remote Code Execution

Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments. The vulnerability allows an unauthenticated attacker to submit a malicious workflow definition containing JavaScript or Python expressions to the Conductor workflow API. Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process. Public proof-of-concept exploit code is available, including a working exploit targeting Conductor v3.23.0. Exploit material has also been published through Exploit-DB, increasing the likelihood of opportunistic scanning and exploitation of exposed deployments.

QuickFox Supply Chain Attack

FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP, enabling selective victim profiling and post-compromise access. The campaign has reportedly been active since August 2025 before being publicly disclosed in August 2026.

WP2Shell RCE

FortiGuard Labs continues to detect exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical unauthenticated remote code execution (RCE) vulnerability affecting WordPress Core. Telemetry collected over the past seven days shows the highest volume of blocked attacks originating from or targeting Poland, Australia, Japan, the United States, and Turkey.
Distributed by aarss.com.
 

Joe's Cable Contact Site


Joe's Cable is always looking for new clients. You may contact us via Telephone, E-Mail, or by filling out the form on this page.

Telephone: 201-289-7613

E-Mail: contact@joescable.com

Web Form:

Name:  

Email:  
Phone:  
Comments:  

     
   

Copyright © 2026 Joe's Cable. All rights reserved.