CISA adds exploited Langflow cross-tenant flaw CVE-2026-55255 to KEV after attackers chain it with older RCE bug

CISA says attackers are already exploiting a critical Langflow flaw and federal agencies must patch it by July 10. The bug, CVE-2026-55255, is a cross-tenant insecure direct object reference issue fixed in Langflow 1.9.1 that lets attackers execute other users’ flows by supplying a flow UUID. Sysdig said attackers paired it with previously patched Langflow remote code execution flaw CVE-2026-33017 after doing host reconnaissance and harvesting flow IDs.
Why it matters: Organizations running Langflow should treat this as urgent because attackers are already chaining it with another flaw to gain code execution. Update to 1.9.1 immediately and review exposed Langflow servers for unauthorized flow execution, reconnaissance, and post-compromise activity.

Sources

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Ionut Arghire 2026.07.08 100% relevant
The existing Langflow tracked story is about a different flaw, CVE-2026-5027, while this article establishes a separate KEV-listed exploitation story centered on CVE-2026-55255 and its chaining with CVE-2026-33017.
← Back to all stories