{"data":{"id":"6f497ed2-3f93-43f9-b1ce-1b72332649bd","title":"CISA orders urgent action on actively exploited Langflow RCE flaw","summary":"A critical vulnerability in Langflow (a visual framework for building AI agents) tracked as CVE-2026-0770 allows attackers to execute code as root (the highest privilege level on a system) without authentication by exploiting how the validate endpoint handles the exec_globals parameter. Attackers are actively exploiting this flaw to deploy malware, steal cloud credentials, and access system information, prompting CISA to order U.S. federal agencies to patch their systems by Friday.","solution":"Organizations operating Langflow should investigate historical requests to /api/v1/validate/code, review host activity, restrict access to the validation functionality, and rotate exposed credentials where successful execution cannot be ruled out. U.S. Federal agencies must follow CISA's Binding Operational Directive (BOD) 26-04 patching guidelines and evaluate each asset's internet exposure.","labels":["security"],"sourceUrl":"https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/","publishedAt":"2026-07-22T11:43:28.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Langflow","Trend Micro","KEVIntel","AWS","JadePuffer ransomware"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-22T11:43:28.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}