Cyber Resilience

Product in the CrosshairsWeekly

In the crosshairs: Langflow leads confirmed exploitation this quarter

Updated 12 August 2026 · Timeframe: Trailing 90 days (CISA KEV additions)

4Langflow3Core3UniFi OS2Internet Explorer2Defender2cPanel Plugin2Catalyst SD-WAN Man…2SharePoint Server2SMA1000 Appliances2SharePoint2FortiSandbox2N-central1Catalyst SD-WAN1Microsoft1Windows
Most-exploited products by KEV, last 90 days (top 15) · security-resilience.ai

Over the last 90 days, Langflow drew 4 CISA-KEV listings, the most of any single product. The chart ranks the 15 products attackers are most actively exploiting right now: a trailing-90-day view, not a legacy all-time list dominated by long-patched software.

Why it matters

The products with the most recent confirmed exploitation are where patch and monitoring attention pays off fastest. If any sit in your estate, they belong at the front of the line.

What to do

Our take

A trailing-90-day exploited-product ranking is the timely version of 'what's under attack' — the list whose changes actually matter.

Earlier issues

Past states of this signal, most recent first.

04 August 2026 In the crosshairs: Langflow leads confirmed exploitation this quarter

Timeframe: Trailing 90 days (CISA KEV additions)

3Langflow3Core3UniFi OS2PAN-OS2LiteLLM2Internet Explorer2Defender2cPanel Plugin2Catalyst SD-WAN Man…2SharePoint Server2SMA1000 Appliances2SharePoint2FortiSandbox1Endpoint Manager Mo…1Catalyst SD-WAN

Over the last 90 days, Langflow drew 3 CISA-KEV listings, the most of any single product. The chart ranks the 15 products attackers are most actively exploiting right now: a trailing-90-day view, not a legacy all-time list dominated by long-patched software.