RCE flaw in IBM's agentic AI platform under active exploitation

A critical remote code execution (RCE) flaw in Langflow, IBM's agentic AI platform, is under active exploitation. The vulnerability affects default deployments, allowing attackers to execute arbitrary code. CISA issued a warning, urging users to patch immediately to prevent further compromise. The extent of the exploitation remains unquantified.

Severity: Critical · Category: Supply Chain

Impact: Remote code execution on IBM's agentic AI platform.

Source: The Register · Aug 05 2026 · Original source

What Happened

A critical vulnerability, identified as CVE-2026-9198, was discovered in Langflow, an IBM-owned low-code AI builder. This flaw allows unauthenticated attackers to execute code remotely on vulnerable default deployments, potentially placing organizations utilizing these instances at immediate risk. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog after identifying evidence of active exploitation. The vulnerability affects Langflow OSS versions 1.0.0 through 1.10.0.

Timeline

Technical Analysis

The vulnerability in default Langflow deployments is a result of chaining two distinct issues that together enable unauthenticated remote code execution. The first issue involves an auto-login endpoint present in default deployments, which is configured to mint superuser tokens to any network caller. The second issue is a code validation endpoint that will execute any Python code provided to it. By combining the easily obtained superuser rights with the ability to run arbitrary Python code, an attacker can achieve remote code execution and potentially take control of the Langflow server. This exploit specifically targets default Langflow deployments where auto-login is enabled and the code validation endpoint is accessible on a network.

Impact

The critical vulnerability allows unauthenticated attackers to execute code remotely on affected Langflow instances. This capability potentially puts organizations running vulnerable default deployments at immediate risk. Successful exploitation of this flaw can lead to an attacker taking over an entire Langflow server, or worse. The vulnerability affects Langflow OSS versions 1.0.0 through 1.10.0. Evidence of active exploitation has been identified, though the full extent of this exploitation is currently unknown.

Discovery & Response

The Cybersecurity and Infrastructure Security Agency (CISA) identified evidence of active exploitation of CVE-2026-9198. Following this discovery, CISA added the CVE to its Known Exploited Vulnerabilities catalog and urged organizations to apply the vendor's mitigation guidance as soon as possible. IBM recommended that affected organizations upgrade Langflow OSS to version 1.10.1 or later, noting that the most recent version at the time of writing was 1.11.2.

How Fencio prevents this

The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.

Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.

All incidents