Three Langflow flaws rated CVSS 9.8 allow unauthenticated RCE
IBM fixed three Langflow OSS vulnerabilities rated CVSS 9.8: CVE-2026-79724, CVE-2026-85025 and CVE-2026-81204. The Dutch NCSC says they can be exploited remotely without authentication or user interaction; the advisory lists 12 CVEs in total, including authorization flaws.
- Three Langflow OSS flaws carry CVSS 9.8 scores
- Exploitable remotely without authentication
- Advisory NCSC-2026-0392 lists 12 CVEs total
- ZoomEye found 18,550 Langflow instances on 23 September
Read next
Security