FR
live
tag

#command-injection

A CVSS 10 flaw turns Kestra into an unauthenticated root shell

On September 2, 2026, CISA added CVE-2026-49869 to its KEV catalog: a CVSS 10 command injection in the open-source orchestrator Kestra, caused by a path comparison that lets any endpoint ending in ’configs’ through. Move to 1.0.45 or 1.3.21 before the September 5 federal deadline, then check whether the instance was already used as an entry point.

Two chained zero-days yield unauthenticated RCE on SonicWall SMA 1000 appliances

On September 1, 2026, SonicWall disclosed two flaws in the SMA 1000 line — a pre-authentication SSRF (CVE-2026-83548, CVSS 10) and an OS command injection (CVE-2026-83549) — already chained in the wild to reach remote code execution without credentials. Apply the hotfix now, and if compromise is confirmed, re-image the appliance instead of patching over the intrusion.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss