CISA added a second Langflow flaw, CVE-2026-0770, to its catalogue of Known Exploited Vulnerabilities (KEV) on 21 July, and set federal agencies a 24 July deadline to patch. Langflow is an open-source framework for building large-language-model (LLM) and agent-orchestration applications, the software layer that wires AI models into automated workflows.
The first Langflow entry, CVE-2025-34291, reached the catalogue on 21 May after Iran-nexus actor MuddyWater exploited it . Two listings for one agent-orchestration framework inside two months put it on the record as a recurring exploitation surface rather than a single incident.
Buyers standing up agent frameworks now inherit the patch-velocity problem that edge appliances have carried for years. Each new AI-application layer adds internet-facing code that attackers probe as fast as vendors and CISA can list the results, and Langflow is the first such framework to earn a repeat entry.
