Kestra OSS OS Command Injection Vulnerability (CVE-2026-49869)
CISA added CVE-2026-49869 to the Known Exploited Vulnerabilities catalog. Affected product: Kestra Kestra OSS. Remediation due date: 2026-09-05.
KEV ✓ EPSS 0.02 CVE-2026-49869 Kestra US
CISA added CVE-2026-49869 to the Known Exploited Vulnerabilities catalog. Affected product: Kestra Kestra OSS. Remediation due date: 2026-09-05.
KEV ✓ EPSS 0.02 CVE-2026-49869 Kestra US
In this article AI workloads are becoming high-value control pointsCase study 1: LiteLLM gateway compromiseCase study 2: RAGFlow compromiseCase study 3: Kestra compromiseMitigation and protection guidanceMITRE ATT&CK techniques observedReferencesLearn more AI is creating a new layer of enterprise infrastructure. Gateways, retrieval platforms, orchestration services, and containerized runtimes now sit between users, applications, data, and models. These systems concentrate credentials, data…
KEV ✓ EPSS 0.84 CVE-2026-42271 CVE-2026-48710 CVE-2026-49869 LiteLLM RAGFlow Kestra US