ZeroDayAlert

CVE-2026-9198: IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM Langflow Added to KEV 2026-08-04 Federal due 2026-08-07 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

IBM Langflow is affected by an unauthenticated code injection vulnerability that permits remote code execution on default deployments. The record does not specify which versions are vulnerable, the scope of "default" configuration, or whether non-default hardening reduces the risk. If you run Langflow and expose it to untrusted network access, treat this as affecting you until you have confirmed otherwise.

How to check whether this touches you

  • Search your infrastructure inventory for Langflow installations, including development, testing and sandbox environments.
  • Determine whether each Langflow instance is reachable from the internet or from untrusted internal networks; prioritise internet-facing or cloud-hosted deployments.
  • Retrieve the running version number from the Langflow application or container metadata and cross-reference against IBM's security advisory for your version's vulnerability and patch status.
  • If you cannot determine the version easily, treat the instance as potentially vulnerable until proven otherwise, given the unauthenticated nature of the attack.

What to do

  1. Obtain IBM's security advisory and patch guidance for this CVE immediately and review the scope of affected versions and available mitigations.
  2. For any Langflow instance you cannot patch within your risk tolerance window, restrict network access: place it behind a firewall, VPN or API gateway that requires authentication, and disable external routing.
  3. Prepare to apply the vendor patch according to CISA BOD 26-04 timelines for your organisation's asset criticality rating.
  4. Enable and retain logs from Langflow and any upstream network security appliances that might record exploitation attempts or successful code execution.
  5. If your Langflow instance is hosted in a cloud service and the vendor cannot provide a patch or mitigation, escalate to your service owner to evaluate discontinuation of the product.

If you find you were exposed

Exploitation of unauthenticated code injection typically occurs before public disclosure, so review logs from at least 90 days before the CISA publication date (2026-08-04) for signs of unusual requests to Langflow endpoints, process execution, or outbound connections. Log retention is your constraint; if your retention is shorter than 90 days, document that gap and focus on artefacts that persist (file modifications, user accounts, scheduled tasks). If you find evidence of compromise, initiate incident response procedures and preserve logs for forensic analysis.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-9198 is being exploited. It cannot tell you whether Langflow is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →