CISA says attackers are actively exploiting a newly tracked flaw in IBM Langflow, a tool used to build AI agents, and federal agencies have three days to secure affected systems. The bug, CVE-2026-9198, is a critical 9.8 remote-code-execution issue on default Langflow deployments that chains two API endpoints to bypass login and run code without authentication; multiple public proof-of-concept exploits appeared in late July.
Why it matters: Organizations running internet-exposed Langflow servers should treat this as urgent because attackers can break in remotely without a password. Update or mitigate immediately, especially if Langflow is reachable from the internet.
2026.08.05
97% relevant
This article adds mainstream reporting and technical context on the same event: CISA has added CVE-2026-9198 to KEV due to active exploitation, and IBM says Langflow OSS 1.0.0 through 1.10.0 should be upgraded to 1.10.1 or later. It also explains the attack chain in default deployments: an auto-login endpoint that can mint superuser tokens and a code-validation endpoint that can execute arbitrary Python code.
Ionut Ilascu
2026.08.05
100% relevant
This article establishes a distinct new exploitation event for Langflow centered on CVE-2026-9198, which is separate from the previously tracked exploited Langflow flaw CVE-2026-0770.
← Back to all stories