CISA Lists Kestra OSS Command Injection Flaw in Exploited Vulnerabilities Catalog
CISA has added CVE-2026-49869, a Kestra OSS OS command injection vulnerability, to its Known Exploited Vulnerabilities Catalog. This critical flaw allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials, posing substantial risks to affected systems. Federal agencies are mandated to remediate this vulnerability promptly.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai