TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/IBM’s Langflow Faces a Critical RCE Under Active Attack as CISA Sets a Three-Day Deadline
News

IBM’s Langflow Faces a Critical RCE Under Active Attack as CISA Sets a Three-Day Deadline

The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies until August 7 to patch a critical remote code execution (RCE) flaw in IBM’s Langflow, an open source...

August 5, 2026 3 Min Read
35

The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies until August 7 to patch a critical remote code execution (RCE) flaw in IBM’s Langflow, an open source platform for building AI agent and retrieval-augmented generation (RAG) workflows. CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities (KEV) catalog on August 4 after confirming active exploitation, and fully functional proof-of-concept exploits have been circulating publicly since late July, according to BleepingComputer.

The flaw carries a maximum-severity 9.8 out of 10 score on the Common Vulnerability Scoring System, and it requires no authentication to exploit. An attacker can take over a default Langflow deployment by chaining two API endpoints: /api/v1/auto_login, which mints a superuser access token for any caller on the network without asking for credentials, and /api/v1/validate/code, which executes arbitrary Python code submitted to it through Python’s exec() function. Chained together, the two endpoints hand a remote, unauthenticated attacker full control of the server, according to the vulnerability’s official description in the National Vulnerability Database.

Langflow is a drag-and-drop, low-code tool for building agentic and RAG workflows, and it has become one of the more widely used open source AI agent builders on the market. IBM inherited the project through acquisition. Langflow was originally built by Logspace, acquired by DataStax in 2024, and folded into IBM when it bought DataStax in 2025. IBM has since built Langflow into watsonx.ai, its enterprise AI development studio, as middleware for constructing agent pipelines, which means the flaw’s reach extends beyond standalone Langflow installs into IBM’s broader AI platform, as The Register reported.

IBM disclosed the vulnerability on July 17 and says it affects Langflow OSS versions 1.0.0 through 1.10.0. The fix shipped in version 1.10.1; the current release is 1.11.2. CISA’s directive requires federal agencies to apply IBM’s mitigation or stop using the product by August 7, under the agency’s Binding Operational Directive 26-04 on risk-based patching. Because exploitation requires no login at all, any organization running a default, internet-reachable Langflow deployment, whether standalone or through watsonx.ai, should treat it as at risk until it is patched and audited.

CVE-2026-9198 was the most severe of three actively exploited flaws CISA added to its KEV catalog in the same update. The other two are a high-severity authentication bypass in N-able’s N-central remote monitoring platform, tracked as CVE-2026-18576, and an incomplete-fix flaw in Apache Tomcat, CVE-2026-34486, which researchers at Palo Alto Networks’ Unit 42 say a Chinese-speaking threat actor already used to plant reverse shells on nine Tomcat servers. The Langflow flaw is also the second critical, actively exploited RCE that CISA has flagged in the platform in as many weeks. The agency issued a similar alert for CVE-2026-0770, a separate root-level code execution bug, roughly two weeks earlier, BleepingComputer reported.

CISA has not disclosed what specific attacks are exploiting the Langflow flaw or said whether it has turned up in ransomware campaigns. But the combination of a public proof-of-concept exploit, a maximum-severity score, and a compressed three-day federal patch deadline makes it one of the more urgent items this week for any organization running Langflow or watsonx.ai. The repeat pattern also points to a broader problem in the current wave of low-code agent builders: tools designed to make AI workflows accessible to non-developers can ship with default configurations, like an open auto-login endpoint, that are difficult to secure once exposed to the internet.

Tags:

AI AgentsCISAIBMLangflowVulnerability Management

Share

Close-up of a padlock and chain locking mechanism, representing verifying npm package integrity to block supply chain compromises
Previous Post

How to Detect Malicious npm preinstall Scripts and Verify Package Integrity

Meta headquarters entrance sign reading 1 Hacker Way with the Meta logo, in Menlo Park, California
Next Post

Meta Says Its Muse Spark AI Model Hacked a Real Company During Testing

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026