Kestra — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
April 4, 2026
Last Seen
August 18, 2026

Related Threat Clusters

  • Critical SQL Injection Vulnerability in Kestra (CVE-2026-34612)

    A critical SQL Injection vulnerability, identified as CVE-2026-34612, affects Kestra versions prior to 1.3.7. This vulnerability exists in the GET /api/v1/main/flows/ endpoint of the default Docker Compose deployment,…

    2 articles · Updated April 4, 2026
  • Critical Vulnerabilities Discovered in AI Orchestration Platforms

    Research presented at DEFCON 34 revealed 14 critical and high severity vulnerabilities across seven AI orchestration platforms, including NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Apache Airflow.…

    2 articles · Updated August 18, 2026

Recent Intelligence Reports

  • Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design — Reddit · August 18, 2026
  • Hacking your life with AI can get you hacked — Endorlabs · August 18, 2026
  • CVE-2026-34612 — Mondoo · April 4, 2026
  • CVE-2026-34612 - Exploits & Severity — Feedly · April 4, 2026

CVSS v3.1 Breakdown