Mark RadarMARK RADAR
EN

CISA Gives Federal Agencies Three Days to Patch Critical Langflow Flaw

1 reports · First detected 2026-07-08 · Last active 2026-07-08

Langflow is a development tool used to build large language model applications and AI workflows. If the vulnerability is exploited, attackers could compromise systems that use the software. The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog is a key resource federal agencies use to prioritize patches.

CISA has added the critical Langflow vulnerability CVE-2026-55255 to its KEV catalog, indicating evidence of exploitation in the wild. The agency ordered U.S. federal agencies to apply patches by July 10, 2026, giving them just three days from the announcement to reduce the risk of attackers infiltrating AI workflows through the flaw.

All Coverage

1 original reports

The Backstory

The history behind this event
CISA Warns Critical Langflow Flaw CVE-2026-33017 Is Being Exploited2026-07-08 · 5 reports · similarity 0.84

Langflow is an open-source development tool for building large language model (LLM) applications and is often connected to cloud services, models and data sources. If remotely compromised, it could give attackers access to AI infrastructure and sensitive credentials, extending the impact beyond a single host.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned in July 2026 that CVE-2026-33017 was being actively exploited. The vulnerability has a CVSS score of 9.3 and affects Langflow versions before 1.8.1. Attackers have used it to steal AI and cloud access keys and mine Monero, and users should upgrade to version 1.9.0 as soon as possible.

Mark Radar|MARK RADAR