www.cisa.gov 8/4/2026, 5:06:09 PM · external

CISA Flags IBM Langflow CVE-2026-9198 Code Injection in KEV List

Developing story vulnerability 2 articles tracked
IBM Langflow Code Injection Vulnerability (CVE-2026-9198) added to CISA KEV list
CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by the Cybersecurity and Infrastructure Security Agency (CISA), serves as a vital resource for cybersecurity professionals to identify and manage vulnerabilities that are actively being exploited. The catalog aids organizations in prioritizing their vulnerability management strategies. As of now, it features a specific vulnerability: CVE-2026-9198, relating to a code injection issue in IBM Langflow, which allows unauthenticated remote code execution.

Organizations are advised to follow vendor guidelines for mitigation and compliance with CISA directives to enhance their security posture.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline