CVE-2026-9198: IBM Langflow's Unauthenticated Remote Code Execution Chain

Technical root cause and active exploitation details for the CVSS 9.8 unauthenticated remote code execution flaw in IBM Langflow.

CVE-2026-9198: IBM Langflow's Unauthenticated Remote Code Execution Chain
Photo by Caspar Camille Rubin / Unsplash
📌
Security Roundup Series: Week of August 3, 2026 • 5 min read deep dive

An unauthenticated remote code execution chain in IBM Langflow—a popular visual framework for building AI and LLM agents—is under active exploitation, allowing remote attackers to achieve arbitrary code execution inside AI deployment pipelines.

🚨
Vulnerability Intelligence: CVE ID: CVE-2026-9198 (CWE-94: Code Injection) Severity & CVSS: Critical 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Exploitation Status: ⚠️ Actively Exploited in the Wild Affected Versions: Langflow prior to patched releases

What's Affected

Langflow instances exposed to untrusted networks without strict authentication layers enabled. Because Langflow serves as an orchestration engine integrating vector stores, model weights, API keys, and enterprise databases, compromising the server compromises all connected AI agents.

The Vulnerability

CVE-2026-9198 enables unauthenticated remote attackers to submit custom flow components that evaluate arbitrary Python code on the underlying host during flow compilation and execution.

Remediation

✅
Action Items: Upgrade Langflow to the latest official release immediately. Ensure Langflow instances are placed behind authentication proxies and never exposed publicly. Rotate all LLM provider API keys (OpenAI, Anthropic, AWS) and database credentials stored in Langflow environment variables.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther