Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route
CISA added CVE-2026-49869, an unauthenticated OS command injection in the Kestra workflow orchestration platform, to its Known Exploited Vulnerabilities catalog after evidence of real attacks. The fla…