A critical pre-authentication code-execution flaw in Orkes Conductor shows how orchestration platforms can become high-value attack surfaces when script evaluation sits too close to the server core.
A critical unauthenticated RCE in Orkes Conductor shows how a workflow engine can become dangerous when runtime-defined JSON is allowed to cross the line into executable code.