{
  "id": 184916,
  "title": "IBM's agentic AI platform is under active attack - patch now",
  "url": "https://urgent.news/2026/08/05/ibms-agentic-ai-platform-is-under-active-attack-patch-now-184916",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-05T16:44:39.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/05/ibms-agentic-ai-platform-is-under-active-attack-patch-now/5283535"
  },
  "original_language": "en",
  "account": "IBM's low-code AI builder, Langflow, has fallen victim to a critical vulnerability that allows unauthenticated attackers to execute code remotely on vulnerable default deployments. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog, urging organizations to apply the vendor's mitigation guidance as soon as possible. IBM advises upgrading to version 1.10.1 or later, with the most recent version being 1.11.2. Langflow, a drag-and-drop GUI for constructing agent workflows, is accessible on Linux, Windows, and macOS. Originally developed by Logspace, now a subsidiary of IBM, the platform was integrated into watsonx.ai, IBM's AI development studio, as middleware that enhances its capabilities. The vulnerability stems from an auto-login endpoint that generates superuser tokens and a code validation endpoint that executes any Python code, which, when combined, could allow an attacker to take over a Langflow server. The exploit was published on July 17, and it is unclear how extensively it has been exploited.",
  "summary": "A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "IBM's agentic AI platform is under active attack - patch now",
        "url": "https://urgent.news/2026/08/05/ibms-agentic-ai-platform-is-under-active-attack-patch-now",
        "published": "2026-08-05T16:44:39.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}