chiprook
← Security
SecurityOctober 8, 2026, 11:20

Three Langflow flaws rated CVSS 9.8 allow unauthenticated RCE

IBM fixed three Langflow OSS vulnerabilities rated CVSS 9.8: CVE-2026-79724, CVE-2026-85025 and CVE-2026-81204. The Dutch NCSC says they can be exploited remotely without authentication or user interaction; the advisory lists 12 CVEs in total, including authorization flaws.

Three Langflow flaws rated CVSS 9.8 allow unauthenticated RCE
#IBM#Langflow
Read next
Security

IBM patches 12 flaws in MQ and Langflow OSS, three rated 9.8

Security

Langflow CVE-2026-0768 with CVSS 9.8 is under active exploitation

Security

CVE-2026-17633: Authenticated RCE in Langflow OSS via /api/v1/custom_component

Security

CVE-2026-69730: CVSS 9.8 RCE in Windows DNS Server in September Patch