Critical 10.0
CVE-2026-49869
Microsoft-reported Kestra CVE-2026-49869 exploited for reverse shell and crypto mining
Vendor / product: Kestra
Event date: 2026-06-26
Public PoC: Yes
First tracked by RiskWire: 2026-09-02
Named threat actors
Qilin (aka Agenda) ransomware
Sources & citations (2)
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners thehackernews.com · 2026-09-03
- Three-of-Seven CISA KEV Additions Now Target AI Infrastructure tech.yahoo.com · 2026-09-03
References
See CVE-2026-49869 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →