Robotics & Physical AIAug 6, 2026

CISA adds an actively exploited Langflow code-injection flaw to the KEV catalog

CISA added CVE-2026-9198, a code-injection vulnerability in IBM Langflow — the visual builder many teams use to assemble LLM agent workflows — to the Known Exploited Vulnerabilities catalog on August 4, 2026, confirming in-the-wild exploitation. TeamCity, Apache Tomcat, and N-able N-central entries landed the same week.

What it means If Langflow is anywhere in your stack, patch now — agent-builder tools are production attack surface, and this one is being exploited in the wild.

Where it came from CISA

Back to the Stream