Redpacketsecurity Multiple High-Risk Vulnerabilities in IBM Langflow OSS Disclosed
Article Content
- •IBM Langflow OSS has multiple high-risk vulnerabilities allowing remote code execution.
- •CVE-2026-93443 and CVE-2026-93445 are critical for internet-accessible deployments.
- •Immediate upgrades and access restrictions are recommended to mitigate risks.
IBM Langflow OSS versions 1.0.0 to 1.12.2 are affected by several vulnerabilities, including CVE-2026-93443 and CVE-2026-93445, which allow remote authenticated attackers to execute arbitrary code. CVE-2026-101331 and CVE-2026-103360 expose sensitive information due to insufficient protections. The vulnerabilities primarily affect self-hosted visual workflow and AI application platforms, especially those accessible over the internet. Attackers can exploit these flaws using low-privilege accounts without user interaction. The urgency for remediation is high, but specific exploitation indicators are not provided. Organizations are advised to upgrade to vendor-fixed releases and restrict network access. The vulnerabilities were disclosed on October 6 and 7, 2026, with CVSS scores ranging from 7.5 to 8.8, indicating significant risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-101331 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Langflow OSS are affected?
What is the risk level of these vulnerabilities?
What actions should organizations take?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…