All incidents

IBM Langflow Code Injection Vulnerability (CVE-2026-9198) added to CISA KEV list

vulnerabilityopenAug 4, 2026 — Aug 4, 2026

CISA has added CVE-2026-9198 to its Known Exploited Vulnerabilities catalogue after confirming that IBM Langflow contains a critical code injection flaw that permits unauthenticated remote code execution. The vulnerability was published in the NVD entry CVE‑2026‑9198 and appears in the KEV list at CISA’s KEV page. This flaw enables attackers to run arbitrary code on affected systems without needing any credentials.

The flaw carries a CVSS v3 score of 9.8, reflecting its potential to compromise confidentiality, integrity and availability. It stems from insufficient input validation in Langflow’s processing engine, allowing an attacker to inject malicious code through a specially crafted request. Because the vulnerable component is exposed by default, any internet‑facing Langflow instance is at risk. No authentication is required to trigger the exploit.

IBM has released a security update that addresses the injection vector and administrators are urged to apply it immediately. Although CISA has not named any specific threat actor exploiting CVE‑2026‑9198, the agency’s decision to list the vulnerability indicates active exploitation in the wild. Organizations should treat the flaw as a priority and verify that the patch has been deployed across all Langflow installations.

The Known Exploited Vulnerabilities catalogue is used by federal agencies and private sector defenders to prioritise remediation of flaws that are already being leveraged by adversaries. By placing CVE‑2026-9198 on the list, CISA signals that defenders must move beyond standard patch cycles and act on this issue without delay. The addition also helps align vulnerability management programmes with the agency’s binding operational directives.

Defenders should begin by confirming the exact version of Langflow running in their environment and applying IBM’s patch as soon as possible. Where immediate patching is not feasible, administrators should restrict network access to the Langflow service, allowing only trusted IP addresses to reach the interface. Enabling detailed logging and monitoring for unexpected process spawns or anomalous outbound connections can help detect any exploitation attempts that may have occurred before patching.

Maintaining an up‑to‑date inventory of all Langflow deployments helps ensure that no instance is overlooked during the remediation process. Teams should also test the patch in a staging environment to verify that it does not disrupt existing workflows before rolling it out to production. Finally, reviewing CISA’s guidance on the KEV catalogue and adhering to any related directives will improve overall resilience against similar threats.

Intelligence briefing updated Aug 4, 2026

CVE-2026-9198 9.8 KEV
Root sourcenvd.nist.gov
Timeline Coverage

Swipe to explore timeline