Threat+Constellation
Live UTC
← Incidents
INCIDENT 408Exploited vulnerabilityLOW / UNDER REVIEWSourcedNew today

CVE-2026-49869 added to CISA KEV: Kestra OSS OS Command Injection Vulnerability

<p>CISA has added seven new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <div class="ListContainerWrapper SCXW190820602 BCX8"> <ul type="disc"> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-9586" target="_blank"><u>CVE-2026-9586</u></a> Sangoma Switchvox SQL Injection Vulnerability&nbsp;</li> </ul> </div> <div class="ListContainerWrapper SCXW190820602 BCX8"> <ul type="disc"> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-4871…

Last evidence update
02 SEP 2026 · 12:00 UTC
Source count
2
Status
reported
GovernmentCVE-2026-49869CVE-2026-9586CVE-2026-48710CVE-2026-59822CVE-2026-82329CVE-2026-83548CVE-2026-83549
Observation history

How this record has evolved as evidence accumulated.

03 SEP · 05:22 UTC
Initial report
03 SEP · 05:22 UTC
Second independent source
03 SEP · 05:22 UTC
Summary updated from new evidence
03 SEP · 05:22 UTC
Related CVE identified (CVE-2026-83549)
Evidence
Related incidents