IBM’s Langflow Faces a Critical RCE Under Active Attack as CISA Sets a Three-Day Deadline
The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies until August 7 to patch a critical remote code execution (RCE) flaw in IBM’s Langflow, an open source...
The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies until August 7 to patch a critical remote code execution (RCE) flaw in IBM’s Langflow, an open source platform for building AI agent and retrieval-augmented generation (RAG) workflows. CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities (KEV) catalog on August 4 after confirming active exploitation, and fully functional proof-of-concept exploits have been circulating publicly since late July, according to BleepingComputer.
The flaw carries a maximum-severity 9.8 out of 10 score on the Common Vulnerability Scoring System, and it requires no authentication to exploit. An attacker can take over a default Langflow deployment by chaining two API endpoints: /api/v1/auto_login, which mints a superuser access token for any caller on the network without asking for credentials, and /api/v1/validate/code, which executes arbitrary Python code submitted to it through Python’s exec() function. Chained together, the two endpoints hand a remote, unauthenticated attacker full control of the server, according to the vulnerability’s official description in the National Vulnerability Database.
Langflow is a drag-and-drop, low-code tool for building agentic and RAG workflows, and it has become one of the more widely used open source AI agent builders on the market. IBM inherited the project through acquisition. Langflow was originally built by Logspace, acquired by DataStax in 2024, and folded into IBM when it bought DataStax in 2025. IBM has since built Langflow into watsonx.ai, its enterprise AI development studio, as middleware for constructing agent pipelines, which means the flaw’s reach extends beyond standalone Langflow installs into IBM’s broader AI platform, as The Register reported.
IBM disclosed the vulnerability on July 17 and says it affects Langflow OSS versions 1.0.0 through 1.10.0. The fix shipped in version 1.10.1; the current release is 1.11.2. CISA’s directive requires federal agencies to apply IBM’s mitigation or stop using the product by August 7, under the agency’s Binding Operational Directive 26-04 on risk-based patching. Because exploitation requires no login at all, any organization running a default, internet-reachable Langflow deployment, whether standalone or through watsonx.ai, should treat it as at risk until it is patched and audited.
CVE-2026-9198 was the most severe of three actively exploited flaws CISA added to its KEV catalog in the same update. The other two are a high-severity authentication bypass in N-able’s N-central remote monitoring platform, tracked as CVE-2026-18576, and an incomplete-fix flaw in Apache Tomcat, CVE-2026-34486, which researchers at Palo Alto Networks’ Unit 42 say a Chinese-speaking threat actor already used to plant reverse shells on nine Tomcat servers. The Langflow flaw is also the second critical, actively exploited RCE that CISA has flagged in the platform in as many weeks. The agency issued a similar alert for CVE-2026-0770, a separate root-level code execution bug, roughly two weeks earlier, BleepingComputer reported.
CISA has not disclosed what specific attacks are exploiting the Langflow flaw or said whether it has turned up in ransomware campaigns. But the combination of a public proof-of-concept exploit, a maximum-severity score, and a compressed three-day federal patch deadline makes it one of the more urgent items this week for any organization running Langflow or watsonx.ai. The repeat pattern also points to a broader problem in the current wave of low-code agent builders: tools designed to make AI workflows accessible to non-developers can ship with default configurations, like an open auto-login endpoint, that are difficult to secure once exposed to the internet.








No Comment! Be the first one.