UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Langflow RCE 2026: CISA's Urgent Patch Order Explained

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

CISA has ordered US federal agencies to patch CVE-2026-0770, a critical, unauthenticated remote code execution flaw in the Langflow AI agent-building framework, by Friday. UK teams running Langflow or similar AI/ML platforms should treat this KEV listing as a live warning, not a US-only compliance footnote.

CVE-2026-0770 exploitation-to-mandate timeline
W0W1W2W3W4Active exploitation first…1w220+ exploitation…1wCISA adds flaw to KEV…1wFederal patch deadline…1wTotal: 4 weeks end-to-end
View the data behind this chart
CVE-2026-0770 exploitation-to-mandate timeline
PhaseStarts (week)Duration (weeks)
Active exploitation first…01
220+ exploitation attempts…11
CISA adds flaw to KEV…21
Federal patch deadline (BOD…31

What CISA actually ordered

On Tuesday, CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog and directed Federal Civilian Executive Branch agencies to remediate it by Friday under Binding Operational Directive 26-04. The flaw sits in Langflow, the open-source visual framework widely used to build AI agents, and lets an unauthenticated attacker achieve remote code execution as root in a low-complexity attack.

Trend Micro researchers, credited with finding and reporting the issue, say the bug lives in how the validate endpoint handles the exec_globals parameter — 'the specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint,' resulting from inclusion of a resource from an untrusted control sphere. In plain terms: a code-execution path inside the application itself, not a misconfiguration at the network edge.

Why the KEV listing matters beyond US federal networks

BOD 26-04 is a US federal directive; it does not legally bind UK organisations. But KEV listings function as a de facto global severity signal — vendors, insurers and regulators increasingly treat inclusion as proof that a flaw is being actively weaponised, not theoretical. For UK infrastructure teams, that means CVE-2026-0770 should be assessed with the same urgency as a formal enforcement notice, even without a UK-specific deadline attached.

Any organisation building AI agent workflows on Langflow, or embedding it in a broader AI/ML stack, should strengthen your vulnerability management strategy around KEV-tracked software specifically, since these are the flaws most likely to trigger audit findings, cyber-insurance queries, or supply-chain due-diligence questions from customers and partners.

How the attacks are actually unfolding

Vulnerability intelligence firm KEVIntel first observed in-the-wild exploitation of CVE-2026-0770 on 27 June 2026, recording over 220 exploitation attempts from 64 unique source IP addresses before CISA formally listed the flaw. KEVIntel founder Ryan Dewhurst told BleepingComputer that activity goes well beyond scanning: attackers have attempted to deploy malware and harvest AWS credentials, environment variables and container metadata from compromised instances.

Dewhurst's guidance is specific and worth repeating for any UK team running Langflow: investigate historical requests to /api/v1/validate/code, review host activity, restrict access to the validation functionality, and rotate any exposed credentials where successful execution cannot be ruled out. Patching alone does not undo a credential theft that already happened.

Illustration: Langflow RCE 2026: CISA's Urgent Patch Order Explained

A repeat offender, not a one-off

CVE-2026-0770 is the fourth Langflow vulnerability CISA has flagged as exploited in the wild in recent years: a missing-authentication flaw (CVE-2025-3248, fixed in Langflow 1.3.0) added to KEV in May 2025, a code injection issue (CVE-2026-33017, affecting versions up to 1.8.1) added in March 2026, and an IDOR authorisation bypass (CVE-2026-55255) added earlier this month. CISA has also confirmed CVE-2025-3248 is being used in ransomware attacks, with cloud security firm Sysdig reporting the JadePuffer gang exploiting it to dump Langflow PostgreSQL databases.

That pattern matters for procurement and architecture decisions: a platform that has produced four exploited-in-the-wild CVEs within roughly a year is not a low-risk dependency to leave unmanaged. Teams evaluating or already running Langflow should treat it as a persistent attack surface requiring ongoing monitoring rather than a one-time patch-and-forget task.

What UK teams should do now

Confirm whether Langflow is deployed anywhere in your environment — including shadow AI projects run by data science teams outside central IT oversight — and check exposure of the validate endpoint to the internet. Apply the vendor patch immediately, restrict outbound network access from Langflow hosts, and keep any Docker sockets or admin interfaces off the public internet. Given the credential-harvesting activity observed, rotate API keys, cloud credentials and database secrets that the Langflow process could reach, even if no compromise is confirmed.

Because a compromised Langflow instance can become a foothold into the wider network, teams should enhance your network security posture around AI/ML infrastructure specifically, and consider managed detection and response services to catch the reconnaissance and lateral-movement behaviour that typically follows an initial RCE. Segmenting AI platforms under Zero Trust principles reduces how far a single unpatched service can spread.

The bigger governance picture for AI platforms

This is the latest in a run of CISA actions covering actively exploited software, alongside recent orders for Cisco flaws and a Joomla plugin issue, reflecting how AI-adjacent infrastructure is now firmly inside the same emergency-patching regime as traditional enterprise software. As AI agent frameworks proliferate across UK organisations, security and compliance teams should also understand the impact of the EU AI Act on UK businesses, since exploited AI tooling sits at the intersection of cyber security enforcement and emerging AI governance obligations.

Buyers assessing where AI workloads run should also factor infrastructure resilience into the equation and optimise your storage for AI and analytics workloads so that credential rotation and incident response don't collide with production data pipelines.

Share
Key takeaways
  • CISA has ordered US federal agencies to patch CVE-2026-0770, a critical unauthenticated RCE in Langflow, by Friday under BOD 26-04.
  • Over 220 exploitation attempts from 64 unique IPs were recorded before the KEV listing, including attempts to steal AWS credentials and cloud metadata.
  • This is the fourth Langflow CVE flagged as actively exploited by CISA, with a related flaw already tied to JadePuffer ransomware attacks.
  • UK teams have no direct BOD obligation but should treat the KEV listing as an urgent signal: patch, restrict the validate endpoint, and rotate exposed credentials.
Frequently asked

FAQs — Langflow RCE 2026

What is CVE-2026-0770?

It's a critical, unauthenticated remote code execution vulnerability in Langflow, caused by unsafe handling of the exec_globals parameter on the validate endpoint, allowing attackers to run code as root.

Does the CISA patch deadline apply to UK organisations?

No, Binding Operational Directive 26-04 is a US federal mandate. However, UK teams running Langflow should still patch urgently given confirmed active exploitation, and can explore our comprehensive cyber security solutions for remediation support.

How is CVE-2026-0770 being exploited in practice?

KEVIntel recorded reconnaissance and command-execution checks alongside attempts to download second-stage scripts and access environment variables, cloud metadata and credential files from vulnerable Langflow instances.

Has Langflow had other serious vulnerabilities?

Yes. CISA has flagged CVE-2025-3248, CVE-2026-33017 and CVE-2026-55255 as exploited in the wild, and CVE-2025-3248 has also been linked to JadePuffer ransomware attacks against Langflow databases.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111