[KEV] CVE-2026-9198: IBM Langflow Code Injection Vulnerability
Active exploitation (KEV)
What to do
- On CISA KEV — actively exploited. Patch immediately.
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
CVE · detail
- CVE-2026-9198KEVEPSS 35%NVD ↗
Sources · 2
outlets reporting the same story — pick one to read