chiprook
← Security
SecurityOctober 6, 2026, 23:40

CVE-2026-49869 in Kestra: internet exposure and the patch-to-KEV gap

Kestra was affected by CVE-2026-49869, an unauthenticated OS command injection rated 10.0 that allows remote code execution. The flaw was fixed in versions 1.0.45 and 1.3.21 released on 2–3 June 2026, and CISA added it to its KEV catalog on 2 September 2026. ZoomEye shows only hundreds of internet-facing instances, though most deployments are internal.

CVE-2026-49869 in Kestra: internet exposure and the patch-to-KEV gap
#Kestra#CISA#ZoomEye
Read next
Security

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869

Security

Kestra CVE-2026-49869: auth bypass via /configs suffix

Security

CISA adds critical Kestra CVE-2026-49869 to KEV catalog

Security

The AI Gateway Becomes a Target: Measuring LiteLLM and Kestra Exposure