Critical RCE Vulnerability in IBM Langflow Under Active Exploitation

Critical RCE Vulnerability in IBM Langflow Under Active Exploitation

First seen 5 Aug 2026, 22:22 UTC TheregisterFieldeffectFeeds.4SysopsForkast.NewsCsa.Sg+8 80.2

Article Content

Browse articles
ThreatCluster

IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability combines an authentication bypass with a code execution flaw, enabling attackers to gain superuser access via the /api/v1/auto_login endpoint and execute code through the /api/v1/validate/code endpoint. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this CVE to its Known Exploited Vulnerabilities catalog on August 4, 2026, following evidence of active exploitation. Organizations using Langflow OSS versions 1.0.0 to 1.10.0 are advised to upgrade to version 1.10.1 or later immediately. The vulnerability has a CVSS score of 9.8, indicating its critical nature, and poses significant risks to organizations that have not hardened their default configurations. The urgency is further emphasized by a federal directive requiring remediation by August 7, 2026.

Key Points: • CVE-2026-9198 allows unauthenticated RCE on default IBM Langflow deployments. • CISA added the vulnerability to its KEV catalog on August 4, 2026, due to active exploitation. • Organizations must upgrade to Langflow version 1.10.1 or later by August 7, 2026.

Timeline

2026-03-20
CVE-2026-33017 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-23
CVE-2026-55255 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-17
CVE-2026-9198 published
IBM disclosed a critical RCE vulnerability in Langflow OSS affecting versions 1.0.0 to 1.10.0.
Fieldeffect
2026-07-17
CVE-2026-8481 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-17
CVE-2026-9103 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-24
First public PoC for CVE-2026-9198
Proof-of-concept code demonstrating the exploit was made publicly available.
Forkast.News
2026-08-04
CISA adds CVE-2026-9198 to KEV catalog
CISA confirmed active exploitation of the vulnerability and urged immediate action from organizations.
Theregister
2026-08-06
Federal agencies face remediation deadline
Under BOD 26-04, federal agencies must remediate or disconnect affected assets by August 7, 2026.
Forkast.News