Active Exploitation of Critical Vulnerability in IBM Langflow OSS (CVE-2026-9198)

Threat actors are actively exploiting a critical code injection vulnerability (CVE-2026-9198, CVSS 9.8) in IBM Langflow OSS, an open-source low-code tool for building AI agents, allowing unauthenticated remote code execution. Users are advised to apply security updates immediately.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai