Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
By exploiting how AI coding agents retrieve and verify plugins, researchers were able to execute malicious code even when the agent was told to use a trusted, approved version.