🔴 Critical  |  Source: CISA Known Exploited Vulnerabilities


A critical code injection vulnerability in IBM Langflow allows unauthenticated attackers to execute arbitrary code on affected deployments without any credentials. The flaw impacts default Langflow configurations, meaning organisations running the platform out of the box are immediately at risk. CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.

Security Architect’s Take: Immediately audit your environment for any internet-exposed Langflow instances and apply the vendor patch before the 7 August 2026 CISA remediation deadline. If patching cannot be completed promptly, restrict network access to Langflow deployments via firewall rules or reverse-proxy authentication controls, and treat any existing deployment as potentially compromised pending investigation.

Original advisory: CVE-2026-9198: IBM Langflow