Feeds.4Sysops
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
Article Content
IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability combines an authentication bypass with a code execution flaw, enabling attackers to gain superuser access via the /api/v1/auto_login endpoint and execute code through the /api/v1/validate/code endpoint. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this CVE to its Known Exploited Vulnerabilities catalog on August 4, 2026, following evidence of active exploitation. Organizations using Langflow OSS versions 1.0.0 to 1.10.0 are advised to upgrade to version 1.10.1 or later immediately. The vulnerability has a CVSS score of 9.8, indicating its critical nature, and poses significant risks to organizations that have not hardened their default configurations. The urgency is further emphasized by a federal directive requiring remediation by August 7, 2026.
Key Points: • CVE-2026-9198 allows unauthenticated RCE on default IBM Langflow deployments. • CISA added the vulnerability to its KEV catalog on August 4, 2026, due to active exploitation. • Organizations must upgrade to Langflow version 1.10.1 or later by August 7, 2026.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.