Threat actors are exploiting CVE-2026-58138, a critical-severity remote code execution vulnerability in Orkes Conductor.
A public PoC for a SQL injection flaw in Apache Superset versions before 6.0.0 could allow authenticated read-level users to trigger error-based SQL injection.