CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws

CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws

First seen 2 Sep 2026, 18:13 UTC Ncsa.QaCisawww.cve.org 74.0

Article Content

Browse articles
ThreatCluster

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2026-9586, a SQL injection vulnerability in Sangoma Switchvox, and several others affecting SonicWall and JFrog products. These vulnerabilities pose significant risks due to active exploitation. Concurrently, IBM has issued a warning about two critical vulnerabilities in Langflow OSS (CVE-2026-19286 and CVE-2026-19285) that allow unauthorized code execution and command injection. The vulnerabilities in Langflow OSS were published in late August 2026, with proof-of-concept code available. Organizations are urged to apply security updates to mitigate risks associated with these vulnerabilities. CISA encourages all organizations to prioritize the remediation of vulnerabilities listed in its KEV Catalog.

Key Points: • CISA added seven new vulnerabilities to its KEV Catalog on September 2, 2026. • IBM warned of critical vulnerabilities in Langflow OSS allowing arbitrary code execution. • Organizations are advised to apply patches and prioritize remediation of listed vulnerabilities.

Timeline

2026-07-17
CVE-2026-9586 published
Sangoma Switchvox SQL Injection vulnerability disclosed, affecting multiple versions.
Cisa
2026-08-08
CVE-2026-19285 published
Langflow OSS vulnerability disclosed, allowing command injection by authenticated users.
Ncsa.Qa
2026-08-28
CVE-2026-19286 published
Langflow OSS vulnerability disclosed, enabling remote code execution without authentication.
Ncsa.Qa
2026-09-02
CISA adds vulnerabilities to KEV Catalog
CISA adds seven vulnerabilities, including CVE-2026-9586, to its Known Exploited Vulnerabilities Catalog.
Cisa