The current version of Kestra is 2.0.5 (as of 05/10/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists this vulnerability in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2026-49869Kestra OSS OS Command Injection Vulnerability
10.0 critical · over the network, without login · CISA deadline was 5 Sept
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 2.0.5 | STABLE | 05/10/2026 | Release notes → |
| 2.0.4 | STABLE | 29/09/2026 | Release notes → |
| 2.0.3 | STABLE | 22/09/2026 | Release notes → |
| 2.0.2 | STABLE | 15/09/2026 | Release notes → |
| 2.0.1 | STABLE | 11/09/2026 | Release notes → |
| 2.0.0 | STABLE | 07/09/2026 | Release notes → |
| 1.3.37 | STABLE | 02/09/2026 | Release notes → |
| 1.3.36 | STABLE | 01/09/2026 | Release notes → |
| 1.3.30 | STABLE | 28/07/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Kestra?
- Kestra 2.0.5, released 05/10/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Kestra release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Kestra updates?
- Tick Kestra off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Kestra version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Kestra version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/kestra)https://patchletter.com/badge/kestra.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).