Active exploitation of Critical Vulnerability in IBM Langflow OSS
6 August 2026
Attackers are actively exploiting a critical vulnerability in IBM Langflow OSS to achieve unauthenticated remote code execution (RCE). Users and administrators of affected products are advised to apply the latest security updates immediately.
Background
Langflow is an open source low-code tool for building Al agents and other Al applications. Security updates have been released to address a critical vulnerability (CVE-2026-9198) affecting IBM Langflow OSS. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10.
Impact
Successful exploitation of this code injection vulnerability could allow an unauthenticated attacker to achieve full remote code execution (RCE) on affected default Langflow deployments.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
The vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.0.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198
