Mark RadarMARK RADAR
About
EN
Sign in

CISA Warns Critical Langflow Flaw CVE-2026-33017 Is Being Exploited

5 reports · First detected 2026-03-30 · Last active 2026-07-08

Langflow is an open-source development tool for building large language model (LLM) applications and is often connected to cloud services, models and data sources. If remotely compromised, it could give attackers access to AI infrastructure and sensitive credentials, extending the impact beyond a single host.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned in July 2026 that CVE-2026-33017 was being actively exploited. The vulnerability has a CVSS score of 9.3 and affects Langflow versions before 1.8.1. Attackers have used it to steal AI and cloud access keys and mine Monero, and users should upgrade to version 1.9.0 as soon as possible.

All Coverage

5 original reports

The Backstory

The history behind this event
CISA Flags Exploited Flaws in IBM Langflow, N-central and Tomcat2026-08-06 · 1 reports · similarity 0.84

The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog sets mandatory remediation priorities for federal agencies and serves as a widely watched warning list for companies. The latest additions affect IBM Langflow, N-central and Apache Tomcat, exposing risks across AI application development, IT management and web server infrastructure as attackers increasingly target widely deployed enterprise software.

CISA added three critical vulnerabilities to the catalog after confirming they were being actively exploited. The most severe is CVE-2026-9198, a code-injection flaw in Langflow carrying a CVSS score of 9.8. It could allow an unauthenticated remote attacker to execute arbitrary code on an affected system. U.S. federal civilian agencies have been directed to apply required mitigations or discontinue vulnerable products by Aug. 7, 2026.

Hackers Exploit Critical Langflow Zero-Day as Patch Remains Unavailable2026-07-22 · 1 reports · similarity 0.89

Langflow is a visual development tool used to build large language model applications and workflows. A critical flaw tracked as CVE-2026-0770 carries a CVSS severity score of 9.8, signaling a high risk to organizations running exposed instances. The vulnerability is especially significant as companies increasingly rely on generative AI development platforms that may connect to sensitive data, models and internal systems.

As of July 22, 2026, attackers had exploited CVE-2026-0770 in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency to add it to its Known Exploited Vulnerabilities catalog. CISA directed federal agencies to address the threat within the required deadline. With no official patch available, security authorities advised organizations to restrict access to Langflow and minimize interactions with affected deployments until a fix is released.

CISA Gives Federal Agencies Three Days to Patch Critical Langflow Flaw2026-07-08 · 1 reports · similarity 0.84

Langflow is a development tool used to build large language model applications and AI workflows. If the vulnerability is exploited, attackers could compromise systems that use the software. The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog is a key resource federal agencies use to prioritize patches.

CISA has added the critical Langflow vulnerability CVE-2026-55255 to its KEV catalog, indicating evidence of exploitation in the wild. The agency ordered U.S. federal agencies to apply patches by July 10, 2026, giving them just three days from the announcement to reduce the risk of attackers infiltrating AI workflows through the flaw.

Attackers Exploit Langflow Path-Traversal Flaw2026-06-15 · 1 reports · similarity 0.84

Langflow is a development tool for building large-language-model applications. Its path-traversal vulnerability, CVE-2026-5027, allows unauthenticated attackers to access server files and potentially execute arbitrary code remotely. The flaw could compromise deployed AI applications, credentials and internal data, posing a significant risk to development and operations teams.

A cybersecurity company recently confirmed that attackers have used CVE-2026-5027 in real-world intrusions in 2026, taking it beyond the proof-of-concept stage. Langflow’s developers patched the vulnerability in version 1.9.0. Organizations running older versions should upgrade as soon as possible and review server file access, anomalous processes and outbound connection logs.

Critical Langflow RCE Flaw Lets Prompt Injection Take Over Servers2026-03-04 · 3 reports · similarity 0.81

Langflow is an open-source, low-code AI workflow platform that can connect large language models with CSV data to build agents. Its CSV Agent hard-codes allow_dangerous_code as True, automatically enabling LangChain's Python REPL. If the service is exposed to the internet, a malicious prompt can execute Python and operating-system commands, putting data, keys and control of the host at risk.

GitHub disclosed CVE-2026-27966 on February 26, 2026. It carries a CVSS 3.1 score of 9.8 and affects all versions before 1.8.0; Langflow patched it in version 1.8.0. Separately, the vulnerability that Sysdig detected being exploited on March 18, about 20 hours after disclosure, was CVE-2026-33017. Six IP addresses attempted attacks within two days, and the patched version for that flaw is 1.9.0.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)