CISA orders US agencies to patch actively exploited Langflow flaw
This digest was compiled by AI from multiple sources — links to the originals are below.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added CVE-2026-0770, a critical remote code execution flaw in the Langflow AI framework, to its Known Exploited Vulnerabilities (KEV) catalog. The order requires Federal Civilian Executive Branch (FCEB) agencies to patch by Friday under Binding Operational Directive (BOD) 26-04. Over 220 exploitation attempts from 64 unique IP addresses were observed since June 27.
The Vulnerability
Tracked as CVE-2026-0770, the flaw allows unauthenticated attackers to achieve remote code execution as root via the exec_globals parameter in Langflow's validate endpoint. Trend Micro researchers identified and reported the issue, describing it as resulting from inclusion of a resource from an untrusted control sphere. The vulnerability is rated critical due to low attack complexity and root-level impact.
Observed Exploitation
KEVIntel first detected in-the-wild exploitation on June 27, logging over 220 attempts from 64 unique source IPs. Founder Ryan Dewhurst reported that malicious payloads included command-execution checks, system reconnaissance, and attempts to download second-stage scripts, access environment variables, cloud metadata, and AWS credentials. Dewhurst urged organizations to investigate historical requests to /api/v1/validate/code and rotate exposed credentials.
CISA's Response
CISA added the flaw to its KEV catalog on Tuesday, mandating FCEB agencies to patch by Friday under BOD 26-04. The agency warned that such vulnerabilities are frequent attack vectors for malicious cyber actors. CISA has previously flagged other Langflow flaws exploited in the wild, including CVE-2025-3248 (used in ransomware attacks by JadePuffer gang), CVE-2026-33017, and CVE-2026-55255.
What's Next
FCEB agencies must complete patching by Friday, July 24, 2026. It remains unclear whether non-government organizations will face similar mandates or if additional Langflow vulnerabilities will be added to the KEV catalog.
1 source
CISA orders US agencies to patch actively exploited Langflow flaw



