Research & KnowledgeEvent: September 2, 2026
Empirical Security published CVE-2026-58138, a 9.8 CVSS vulnerability affecting Netflix's Conductor workflow engine, which is unauthenticated and unsandboxed, with confirmed exploitation in the last 7 days.
Published
Signal category
Research & Knowledge
Quote
“Our latest CVE of the Month breaks down CVE-2026-58138: how an unauthenticated attacker gets remote code execution through an unsandboxed script evaluator, why your vulnerability scanner won't catch it, and exactly how to hunt for it in your environment.”
— Empirical Security team
Company
Empirical Security
Security Intelligence and Decision Support, Tailored to your Enterprise.
- Industry
- Computer and Network Security
- Location
- Chicago, US
- Company size
- 31 employees
Empirical builds mathematical models for security data. We maintain the world’s most advanced global models for cybersecurity, and we build local models that respond to your enterprise’s specific context and threat landscape.
Founded 2024