[NEW] [high] IBM Langflow Desktop OSS: Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in IBM Langflow Desktop OSS to gain administrative privileges, execute arbitrary code, bypass security measures, manipulate and disclose data, or cause a Denial-of-Service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in IBM Langflow Desktop OSS can lead to administrative privilege escalation, arbitrary code execution, security bypass, data manipulation, disclosure, or Denial of Service.
- Who is affected
- Users of IBM Langflow Desktop OSS are affected by these vulnerabilities.
- Urgency
- Remediation is high priority due to the variety of potential impacts including privilege escalation and code execution.
- Action
- Update to the latest version of IBM Langflow Desktop OSS to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Langflow Desktop OSS
Get an email when a new Langflow Desktop OSS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2410
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-76670.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-77540.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-77550.75% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-78720.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-80560.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-84760.97% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 60% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-84810.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-85050.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-86350.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-88590.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7667 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7754 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7755 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7872 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8056 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8476 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8481 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8505 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8635 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8859 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9103 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9135 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9198 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9202 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedIBM security advisory (AV26-770)cccs
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-9198: IBM Langflow Code Injection Vulnerabilitycisa-kev
- unknownNCSC-2026-0251 [1.00] [M/H] Vulnerabilities fixed in IBM Langflow OSSncsc-nl
- criticalCVE-2026-8859: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files…nvd
- criticalCVE-2026-8635: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to supe…nvd
- criticalCVE-2026-8505: IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication …nvd
- criticalCVE-2026-8481: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in…nvd
- criticalCVE-2026-8476: IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in…nvd
- highCVE-2026-8056: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component paramete…nvd
- highCVE-2026-7872: IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files …nvd
- highCVE-2026-7755: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incompl…nvd
Recent advisories for IBM Langflow Desktop OSS
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] IBM Langflow Desktop OSS: Vulnerability allows information disclosurecert-bund · 2026-07-31
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11