Exploited Known exploited (KEV) CVE-2026-9198

An AI development tool taken over in its default deployment - code injection in Langflow (CVE-2026-9198)

IBM Langflow Added to KEV Aug 4, 2026 Federal remediation due 2026-08-07

A code injection vulnerability in IBM Langflow has been added to CISA's Known Exploited Vulnerabilities catalog. Unauthenticated attackers can achieve full remote code execution on default deployments.

Key facts

  • CVE IDCVE-2026-9198
  • Affected (vendor / product)IBM Langflow
  • CWECWE-94
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-08-07 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Code injection (CWE-94) allows unauthenticated attackers to achieve full remote code execution.
  • CISA states explicitly that it holds on default Langflow deployments.
  • It does not arise from misconfiguration, so an audit passes it over if the deployment matches the default.
  • Langflow is a development tool for assembling language-model applications through a visual interface.
  • Of the 1,687 KEV records this site holds as of 2026-09-02, 72 include CWE-94 and eight concern IBM products.
  • The due date is three days after addition; only 86 of the 1,687 carry a three-day deadline.

1The weight of "default deployments"

CISA's description says the vulnerability holds on default Langflow deployments. It is not dangerous because something was misconfigured; it is dangerous as it stands when brought up.

A vulnerability from misconfigurationA vulnerability holding in the default state (this case)
An audit can find itAn audit passes it over if it matches the default
Operational measures can close itNothing closes it until the update is applied
The effect is limited to misconfigured environmentsIt reaches every environment brought up as it is

Environments stood up for evaluation mid-development are exactly the ones left at their defaults. That the stage before production design becomes the way in is what makes this shape awkward in practice.

2Development tools as a target

KEV records held by this site1,687CISA catalog of exploited vulnerabilities
Records including code injection (CWE-94)72CWEs run to 176 kinds overall
Records for IBM products8281 vendors in total
Due datethree days86 records carry a three-day deadline

Langflow is a development tool for assembling applications that use language models through a visual interface. A development tool appearing in KEV shows attackers targeting not only production services but the development environments in front of them. Development environments often hold credentials and test data, opening a path onward into production.

3Unauthenticated, straight to full execution

That CISA writes "unauthenticated attackers can achieve full remote code execution" states the seriousness plainly. There is no authentication at the entrance and code execution at the destination, with no intervening stage. The three-day deadline reads as following from that directness.

Why it matters

Environments stood up for development or evaluation fall outside asset management easily and are left at their defaults for long periods. They often hold credentials and test data, opening a path onward into production. An AI development tool appearing in KEV shows that taking stock of development environments, not only production services, is required.

FAQ

Can reviewing configuration prevent it?
According to CISA it holds on default deployments, so reviewing configuration does not close it. An update per vendor instructions is required.
What is Langflow?
A development tool for assembling applications that use language models through a visual interface.
Why is the deadline three days?
CISA gives no reason, though the directness - no authentication required, full remote code execution at the destination - reads as the background.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#CISA#Langflow#code injection#AI development tools#CWE-94
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.