YogSotho[verified]@YogSoth0General
The post lists several high‑severity CVEs for Kestra, identifies the types of vulnerabilities, and outlines potential impacts, but it offers no PoC, exploit, or mitigation details.
Netlas.io[verified]@Netlas_ioDisclosure
Newly disclosed RCE vulnerabilities in Kestra (CVE-2026-49869 & CVE-2026-53576) rated 10/10, allowing unauthenticated attackers to execute code as root. No PoC, exploit, patch, or active exploitation evidence is provided.
Lyrie.ai[verified]@lyrie_aiDisclosure
This snippet discloses high‑severity CVEs with brief technical details, but provides no PoC, exploit code, or patch information.
DFIR Lab[verified]@DFIR_LabPatch
A critical CVE-2026-53576 in the Kestra orchestration platform allows unauthenticated root RCE (CVSS 10.0); immediate patching is required.
ADK Cyber[verified]@ADKCyberPatch
The tweet announces CVE-2026-53576 with a CVSS 10.0 score affecting Kestra and urges immediate patching, but it does not mention exploits, PoC, or active attacks.
pdnuclei-bot@pdnuclei_botDisclosure
The post announces CVE-2026-53576 as a critical authentication bypass that results in remote code execution in Kestra ≤ 1.3.20, and directs readers to a Nuclei template for further details.
CVE@CVEnewDisclosure
The CVE identifies a flaw in Kestra's REST API authentication filter in versions before 1.0.45 and 1.3.21, with patches available in newer releases.
SecAlerts@SecAlertsCoPatch
CVE-2026-53576 enables unauthenticated remote code execution in Kestra through a crafted /configs path, scoring 10 on CVSS. The vulnerability has been patched in releases 1.0.45 and 1.3.21, which are recommended for all affected installations.