Skip to main content

Cybersecurity Weather

Global observatory

← Vulnerabilities

CVE-2026-9198

IBM Langflow

EPSS 17%KEV

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

Published
Last modified
CISA KEV
Yes
Ransomware use
Not indicated

Official sources

CVE-2026-9198 | Cyber Weather Index