CISA KEV Alert 7/21/2026, 3:33:04 PM

CISA warns of critical Langflow RCE flaw CVE-2026-0770

Developing story vulnerability 3 articles tracked
WordPress core flaw chain (CVE-2026-60137, CVE-2026-63030) exploited for remote code execution
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-0770 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects Langflow’s Langflow product and is described as the Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability. In one sentence, the vulnerability permits remote attackers to execute arbitrary code on vulnerable installations.

The issue is an inclusion of functionality from an untrusted control sphere, which allows an unauthenticated attacker to send specially crafted requests that lead to remote code execution. The vulnerability has a CVSS base score of 9.8, rating it as critical. No patch or advisory has been made public at this time, and the patch status is listed as unknown.

Because the CVE appears in the KEV catalogue, active exploitation has been confirmed in the wild. There is no publicly known link to ransomware campaigns at present. CISA has set a remediation deadline of 24 July 2026 for federal agencies to address the flaw.

CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

This directive binds Federal Civilian Executive Branch (FCEB) agencies; all other organisations should review their exposure and apply any available mitigations.

For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-0770 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline