Product in the CrosshairsWeekly
In the crosshairs: Langflow leads confirmed exploitation this quarter
Updated 12 August 2026 · Timeframe: Trailing 90 days (CISA KEV additions)
Over the last 90 days, Langflow drew 4 CISA-KEV listings, the most of any single product. The chart ranks the 15 products attackers are most actively exploiting right now: a trailing-90-day view, not a legacy all-time list dominated by long-patched software.
Why it matters
The products with the most recent confirmed exploitation are where patch and monitoring attention pays off fastest. If any sit in your estate, they belong at the front of the line.
What to do
- Security leaders. Cross-check this list against your asset inventory; a top-exploited product you run is an immediate priority.
- Lean IT orgs. If you run anything on this list, its KEV items are same-week work.
- MSPs. Sweep client fleets for the products topping the recent exploited list; a rising product is an outreach reason.
Our take
A trailing-90-day exploited-product ranking is the timely version of 'what's under attack' — the list whose changes actually matter.
Earlier issues
Past states of this signal, most recent first.
04 August 2026 In the crosshairs: Langflow leads confirmed exploitation this quarter
Timeframe: Trailing 90 days (CISA KEV additions)
Over the last 90 days, Langflow drew 3 CISA-KEV listings, the most of any single product. The chart ranks the 15 products attackers are most actively exploiting right now: a trailing-90-day view, not a legacy all-time list dominated by long-patched software.