Skip to content
English

Products › Brands

Brand

Kestra: actively exploited vulnerabilities

1 vulnerability in a Kestra product (Kestra OSS) is in CISA’s catalog of exploited vulnerabilities. It was added on September 2, 2026.

By category

Add just one Kestra category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Kestra OSS 1 vulnerability · AI and automation

Name used by CISA: Kestra. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Kestra list.

  1. Rank 1Kestra OSS

    CVE-2026-49869

    Recently addedHunt for compromise (CISA)

    Kestra OSS OS Command Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)

Follow and verify

Indicative classification, based on the vendor and product names given by CISA. How products are classified.