CRITICAL: Langflow CVE-2026-9198 Hits CISA KEV as Exploit Code Spreads
IBM Langflow carries a CVSS 9.8 unauthenticated remote code execution flaw, CVE-2026-9198, that chains a token minting auto-login endpoint with a code validation endpoint running exec(). CISA added it to the Known Exploited Vulnerabilities catalog with an August 7 federal deadline, public exploit code is circulating, and roughly 7,000 instances are reachable online. Upgrade to 1.10.1 or later and rotate every secret the instance could read.