CVE-2026-9198: IBM Langflow Code Injection Vulnerability

Summary

IBM Langflow has a critical code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default deployments. Users are instructed to apply vendor mitigations and follow CISA's guidance on prioritizing security updates and forensic triage requirements.

IFF Assessment

FOE

This vulnerability allows for remote code execution, posing a significant threat to systems using IBM Langflow.

Severity

9.8 Critical

The vulnerability allows for unauthenticated remote code execution on default deployments, indicating a high attack vector and complete impact on confidentiality, integrity, and availability, resulting in a critical CVSS score.

CISA KEV: Listed as actively exploited. Federal patch due: August 07, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in IBM Langflow enables unauthenticated remote code execution, a severe risk that defenders must address urgently. Prioritizing patching and applying vendor-specific mitigations, as guided by CISA, is crucial to prevent exploitation.

Read Full Story →