CVE-2026-9198
exploitation · critical · Evidence score 90
- Vendor
- IBM
- Affected software
- IBM Langflow
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.17053
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Provenance
CISA Known Exploited Vulnerabilities
4 August 2026, 10:00 AM AEST