Langflow CVE-2026-9198 entered the CISA KEV list on 4 August 2026: patch to 1.10.1 and close 3 gaps
CVE-2026-9198 chains two Langflow API endpoints into unauthenticated remote code execution on default deployments. IBM rates it CVSS 9.8, CISA calls it exploited, and the fix is a version bump plus three configuration