Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-49869
CVE
CVE-2026-49869
View on NVD ↗
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
MITRE ATT&CK TTPs
1
T1059.001
PowerShell
Execution
Source Articles
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM. Threat actors are exploiting these vulnerabilities to deploy reverse shells, execute arbitrary code, steal credentials, and deploy cryptocurrency miners. Exploitation of CVE-2026-83548 and CVE-2026-83549 in SonicWall devices has been confirmed, while CVE-2026-9586 and CVE-2026-82329 are being used to gain administrative access and conduct post-exploitation activities. Microsoft and Wiz report active exploitation of CVE-2026-42271 and CVE-2026-48710 in LiteLLM deployments, with attackers achieving remote code execution and stealing API keys, and CVE-2026-49869 in Kestra being used to establish reverse shells and deploy miners.
hacker-news
Sep 3, 2026