Our takeCISA adds CVE-2026-0770 to KEV: unauthenticated remote code execution in Langflow, exploitation confirmed. Langflow instances get spun up for AI experiments and forgotten — whether you're an enterprise lab or a two-person shop, find yours, get it off the open internet, patch.Cyber Resilience desk
Sources (5)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- hackernews · hackernews
- hackernews · hackernews
What this means for you — Security leader:Confirm whether any Langflow instances run in your environment, especially internet-facing ones tied to AI/LLM pipelines, and patch per CISA's KEV deadline — exploitation is already confirmed.
What this means for you — Lean IT orgs:If your team uses Langflow to build AI workflows, update it now; if you don't run Langflow or similar low-code AI tools, this one doesn't apply to you.
What this means for you — MSP:Scan all client environments for Langflow deployments — it's often spun up ad hoc for AI prototyping and easy to miss in asset inventories — and patch or take exposed instances offline first.
What this means for you — Researcher:Worth digging into how Langflow's flow-import/plugin-loading mechanism handles external code — the CWE class (inclusion of functionality from untrusted control sphere) suggests a template or deserialization-style injection point.