that AI agent builder you self-hosted? attackers don't even need a password to take it over

CVE-2026-9198 lets anyone run code on a default Langflow install with zero credentials — CISA gave federal agencies two days to patch it.

Aliteq
Lena Fischer · AI & Local Compute Editor

The short version

CVE-2026-9198 is a code-injection bug in Langflow that lets an unauthenticated attacker achieve full remote code execution on default installs.

The short version

It carries a CVSS score of 9.8 out of 10 — about as severe as this scoring system goes.

The short version

Langflow fixed it in version 1.10.1, released in July 2026.

The short version

CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 5, 2026, giving federal agencies a 48-hour deadline.

The short version

It's the third Langflow RCE weaponized in the wild in 2026, after CVE-2026-0770 in June and CVE-2026-33017 in March.

My take

Self-hosted AI orchestration tools are turning into 2026's WordPress plugins: fast-moving, feature-first, thin on security review, and now three critical RCEs in one product inside eight months. I…

Aliteq

Read the full story

that AI agent builder you self-hosted? attackers don't even need a password to take it over

Read the full story on Aliteq