IBM patches critical Langflow OSS flaws with CVSS 9.8 scores, no auth required
IBM released fixes for twelve vulnerabilities across IBM MQ, IBM MQ Appliance, and Langflow OSS, with Dutch cybersecurity agency NCSC summarising them in advisory NCSC-2026-0392 on 23 September 2026. Three Langflow OSS flaws — CVE-2026-79724, CVE-2026-85025, and CVE-2026-81204 — scored 9.8 on the CVSS v3 scale and can be exploited without any authentication, enabling arbitrary code or OS command execution. Because Langflow services typically hold credentials for model providers, datastores, and third-party APIs, successful exploitation could expose those secrets to attackers. A ZoomEye scan conducted on the same date identified over 18,500 fingerprinted Langflow instances publicly reachable online. Teams are advised to upgrade to IBM's fixed builds immediately, restrict network access during rollout, and rotate any provider keys stored within the platform after patching.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in