CVE-2026-9198 · Critical · CISA KEV
IBM Langflow Code Injection: Unauthenticated RCE in Default Deployments
Threat Engine Auto-Feed · data current as of 2026-08-05
CVE-2026-9198 is a critical code injection vulnerability in IBM Langflow, allowing unauthenticated attackers to achieve full remote code execution. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has a high EPSS percentile, indicating significant exploitability.
- CVSS:
- EPSS percentile: 0.96771
- Exploitation pressure: 83/100 (Critical)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 97th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability involves a code injection flaw, meaning an attacker can supply malicious code as input to the application, which the application then executes. This bypasses intended security controls and allows the attacker to run arbitrary commands on the underlying system.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using IBM Langflow in default configurations
- Enterprises in Financial Services and Technology sectors, given observed adversary targeting
Misconfigurations that escalate it
- Deployment of IBM Langflow without proper input validation or sandboxing mechanisms
- Running Langflow with excessive privileges
High-impact scenarios
- Complete system compromise and data exfiltration due to remote code execution
- Disruption of Langflow services and potential lateral movement within the network
- Ransomware deployment or espionage, particularly by financially motivated groups or state-sponsored actors
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor Langflow logs for unusual process execution or unexpected outbound connections originating from the Langflow environment
- Implement network intrusion detection systems (NIDS) to flag suspicious activity related to Langflow deployments
Contain
- Isolate affected Langflow instances from the network to prevent further compromise
- Review and restrict network access to Langflow deployments to only necessary services and users
Patch
- Apply the latest security patches and updates provided by IBM for Langflow immediately
Frontier verdict — Critical
Critical priority due to active exploitation (CISA KEV) and unauthenticated remote code execution in default IBM Langflow deployments.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.