Skip to content
COOEY

EXPOSURES › CVE-2026-9198

CVE-2026-9198

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-9198 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

IBM Langflow Code Injection Vulnerability allows RCE.

IBM Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. This high-risk vulnerability, actively exploited, poses a significant threat to organizations using Langflow. Immediate action is required to mitigate this risk.

Shame score — High-risk vulnerability actively exploited, allowing full remote code execution on default deployments.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

AFFECTED FEDRAMP PRODUCTS · 5
PRODUCTSTATUS
IBM Cloud for Government
IBM
Authorized
IBM Federal HR Cloud
IBM
Authorized
IBM Maximo and TRIRIGA on Cloud for U.S. Federal
IBM
Authorized
MaaS360 Enterprise Mobility Management
IBM
Authorized
SmartCloud for Government
IBM
Authorized