CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. government agencies to address a critical vulnerability in Langflow, a visual framework used for building AI agents. The flaw, tracked as CVE-2026-0770, enables unauthenticated attackers to achieve remote code execution with minimal effort. This vulnerability was recently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation under Binding Operational Directive 26-04. Trend Micro researchers identified the issue in how Langflow processes the exec_globals parameter, allowing attackers to run arbitrary code as root. According to KEVIntel, over 220 exploitation attempts have been recorded since mid-June, with malicious payloads observed stealing AWS credentials and deploying malware.