CISA KEV Alert 8/4/2026, 4:57:08 PM

Critical IBM Langflow Flaw Exploited, Patch Urged by CISA

Developing story vulnerability 2 articles tracked
IBM Langflow Code Injection Vulnerability (CVE-2026-9198) added to CISA KEV list
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

ON 4 August 2026 the Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑9198 to its Known Exploited Vulnerabilities (KEV) catalogue. The entry concerns IBM’s Langflow platform and is titled the IBM Langflow Code Injection Vulnerability. In brief, the flaw permits unauthenticated attackers to execute arbitrary code on systems running the default Langflow deployment.

The vulnerability is a code injection bug that can be triggered remotely without authentication, leading to full remote code execution on the affected host. The Common Vulnerability Scoring System rates it at 9.8, which is classified as CRITICAL. IBM has released a patch that addresses the issue, and administrators are advised to apply it promptly.

Because the vulnerability is listed in the KEV catalogue, CISA confirms that it is being actively exploited in the wild. At present there is no publicly known link to ransomware campaigns. Federal civilian executive branch (FCEB) agencies must remediate the flaw by 7 August 2026, in line with the due date assigned by CISA.

CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.

While the directive binds FCEB agencies, all organisations should review their Langflow installations for exposure and apply the available patch or other mitigations as soon as possible.

For full technical details, refer to the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-9198 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline