CVE-2025-26074

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

Published 2025-06-30. Last modified 2026-06-17.