CVE-2026-9198 · Critical · CISA KEV

IBM Langflow Code Injection: Unauthenticated RCE in Default Deployments

Threat Engine Auto-Feed · data current as of 2026-08-05

CVE-2026-9198 is a critical code injection vulnerability in IBM Langflow, allowing unauthenticated attackers to achieve full remote code execution. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has a high EPSS percentile, indicating significant exploitability.

  • CVSS:
  • EPSS percentile: 0.96771
  • Exploitation pressure: 83/100 (Critical)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 97th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability involves a code injection flaw, meaning an attacker can supply malicious code as input to the application, which the application then executes. This bypasses intended security controls and allows the attacker to run arbitrary commands on the underlying system.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using IBM Langflow in default configurations
  • Enterprises in Financial Services and Technology sectors, given observed adversary targeting

Misconfigurations that escalate it

  • Deployment of IBM Langflow without proper input validation or sandboxing mechanisms
  • Running Langflow with excessive privileges

High-impact scenarios

  • Complete system compromise and data exfiltration due to remote code execution
  • Disruption of Langflow services and potential lateral movement within the network
  • Ransomware deployment or espionage, particularly by financially motivated groups or state-sponsored actors

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor Langflow logs for unusual process execution or unexpected outbound connections originating from the Langflow environment
  • Implement network intrusion detection systems (NIDS) to flag suspicious activity related to Langflow deployments

Contain

  • Isolate affected Langflow instances from the network to prevent further compromise
  • Review and restrict network access to Langflow deployments to only necessary services and users

Patch

  • Apply the latest security patches and updates provided by IBM for Langflow immediately

Frontier verdict — Critical

Critical priority due to active exploitation (CISA KEV) and unauthenticated remote code execution in default IBM Langflow deployments.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.