Kestra, 10 out of 10: the flaw that does not need to face the internet
On 2 September 2026 CISA added seven exploited flaws to the KEV catalog. Three were perimeter appliances; another three are services your own team stood up (JFrog Artifactory, Kestra and LiteLLM), and the seventh, Starlette, nobody installed at all. The Kestra one scores 10.0 and opens because an authentication filter uses endsWith instead of an exact comparison. And the advisory says internet exposure is not required: reaching the port from inside is enough. What that changes in your patching queue.