IBM patches 12 flaws in MQ and Langflow OSS, three rated 9.8
IBM released fixes for twelve vulnerabilities in IBM MQ, MQ Appliance and Langflow OSS; three Langflow flaws (CVE-2026-79724, CVE-2026-85025, CVE-2026-81204) carry a CVSS score of 9.8 and need no authentication, allowing arbitrary code and OS command execution. ZoomEye found 18,550 Langflow instances exposed online.
- Three Langflow OSS flaws rated 9.8 require no authentication
- Remaining Langflow issues rated 8.8 need an authenticated session
- ZoomEye found 18,550 Langflow instances online on September 23
- Main risk is exposure of credentials to models, datastores and APIs
Read next
Security