Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Langflow hits KEV a second time

1 min read
18:20UTC

CISA listed a second Langflow flaw, CVE-2026-0770, on 21 July, two months after Iran-nexus MuddyWater exploited the framework's first catalogued bug.

TechnologyAssessed
Key takeaway

A second Langflow KEV entry in two months shows AI-agent frameworks drawing repeat exploitation.

CISA added a second Langflow flaw, CVE-2026-0770, to its catalogue of Known Exploited Vulnerabilities (KEV) on 21 July, and set federal agencies a 24 July deadline to patch. Langflow is an open-source framework for building large-language-model (LLM) and agent-orchestration applications, the software layer that wires AI models into automated workflows.

The first Langflow entry, CVE-2025-34291, reached the catalogue on 21 May after Iran-nexus actor MuddyWater exploited it . Two listings for one agent-orchestration framework inside two months put it on the record as a recurring exploitation surface rather than a single incident.

Buyers standing up agent frameworks now inherit the patch-velocity problem that edge appliances have carried for years. Each new AI-application layer adds internet-facing code that attackers probe as fast as vendors and CISA can list the results, and Langflow is the first such framework to earn a repeat entry.

Deep Analysis

In plain English

Langflow is free, open-source software that lets developers build AI chatbot and agent pipelines by dragging and connecting blocks instead of writing code from scratch. Because it often stores passwords and access keys for other services it connects to, a security flaw in Langflow can give an attacker access well beyond Langflow itself. On 21 July, CISA added a second Langflow flaw, CVE-2026-0770, to its list of vulnerabilities under active attack, giving US federal agencies until 24 July to fix it. This is the second Langflow flaw added to that list within two months, a fast repeat for one piece of software.

Deep Analysis
Root Causes

Langflow's structural exposure comes from its role as an orchestration layer: because it stores API tokens and credentials for every downstream service a pipeline connects to, a single flaw gives an attacker a pivot point reaching every service the pipeline touches, well beyond the Langflow instance itself.

A second KEV entry within two months suggests the codebase's attack surface, built for rapid feature delivery in a fast-moving open-source AI tooling project, has not yet had the multiple rounds of hardening review that longer-established infrastructure software has undergone.

Escalation

No threat actor has yet been publicly attributed to CVE-2026-0770, unlike Langflow's first KEV entry which was tied to MuddyWater.

What could happen next?
  • Risk

    Langflow's second KEV entry in two months marks it as a recurring exploitation surface rather than a one-off flaw, raising the odds of a third entry if the underlying hardening gap is not addressed.

  • Consequence

    Organisations running Langflow now face two separate federal-deadline patch cycles within two months, straining the same patching resources used for other KEV entries in this fortnight's batch.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

CISA· 24 Jul 2026
Read original
Causes and effects
This Event
Langflow hits KEV a second time
A second exploited-vulnerabilities entry in two months puts AI-agent-orchestration software on the recurring-exploitation trajectory long familiar from edge appliances.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.