{
  "id": 10049555,
  "title": "What the September 2026 IBM advisory means for teams running Langflow OSS in production",
  "url": "https://urgent.news/2026/09/26/what-the-september-2026-ibm-advisory-means-for-teams-running-langflow",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-26T19:20:44.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kozhevniko/what-the-september-2026-ibm-advisory-means-for-teams-running-langflow-oss-in-production-1l7b"
  },
  "original_language": "en",
  "account": "The IBM advisory from September 2026 addresses twelve vulnerabilities across IBM MQ, IBM MQ Appliance, and Langflow OSS. Langflow OSS is notably impacted by three critical vulnerabilities (CVE-2026-79724, CVE-2026-85025, and CVE-2026-81204) that can be exploited without authentication, allowing for code injection and operating system command execution.\n\nThese unauthenticated issues pose a significant risk in production environments, as they could lead to credential exposure. Langflow services typically authenticate to various external services like model providers, datastores, and third-party APIs. An attacker gaining control over the Langflow service could potentially access these credentials, enabling unauthorized access to other systems.\n\nAccording to the advisory, there are currently 18,550 instances of Langflow OSS in use globally, identified through a ZoomEye search. However, this number includes potential matches rather than confirmed vulnerable systems.\n\nTo mitigate the risk, users of Langflow OSS are advised to upgrade to the latest fixed builds provided by IBM. Critical steps include verifying the upgraded version and restricting access to the service post-upgrade. Additionally, hosts running Langflow should be isolated from sensitive secret storage, and any keys used by flows for provider authentication should be rotated after the patch to prevent potential exploitation of outdated credentials.",
  "summary": "What the September 2026 IBM advisory means for teams running Langflow OSS in production Vulnerability overview IBM shipped fixes for twelve vulnerabilities affecting IBM MQ, IBM MQ Appliance and Langflow OSS. The Dutch NCSC summarised them in advisory NCSC-2026-0392 on 23 September 2026. Langflow OSS accounts for several entries, three of which, CVE-2026-79724, CVE-2026-85025 and CVE-2026-81204,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}