IBM's agentic AI platform is under active attack - patch now
A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
IBM's low-code AI builder, Langflow, has fallen victim to a critical vulnerability that allows unauthenticated attackers to execute code remotely on vulnerable default deployments. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog, urging organizations to apply the vendor's mitigation guidance as soon as possible.
IBM advises upgrading to version 1.10.1 or later, with the most recent version being 1.11.2. Langflow, a drag-and-drop GUI for constructing agent workflows, is accessible on Linux, Windows, and macOS. Originally developed by Logspace, now a subsidiary of IBM, the platform was integrated into watsonx.ai, IBM's AI development studio, as middleware that enhances its capabilities.
The vulnerability stems from an auto-login endpoint that generates superuser tokens and a code validation endpoint that executes any Python code, which, when combined, could allow an attacker to take over a Langflow server. The exploit was published on July 17, and it is unclear how extensively it has been exploited.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- IBM's agentic AI platform is under active attack - patch now theregister.com