Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Langflow hits KEV a second time

1 min read
18:20UTC

CISA listed a second Langflow flaw, CVE-2026-0770, on 21 July, two months after Iran-nexus MuddyWater exploited the framework's first catalogued bug.

TechnologyAssessed
Key takeaway

A second Langflow KEV entry in two months shows AI-agent frameworks drawing repeat exploitation.

CISA added a second Langflow flaw, CVE-2026-0770, to its catalogue of Known Exploited Vulnerabilities (KEV) on 21 July, and set federal agencies a 24 July deadline to patch. Langflow is an open-source framework for building large-language-model (LLM) and agent-orchestration applications, the software layer that wires AI models into automated workflows.

The first Langflow entry, CVE-2025-34291, reached the catalogue on 21 May after Iran-nexus actor MuddyWater exploited it . Two listings for one agent-orchestration framework inside two months put it on the record as a recurring exploitation surface rather than a single incident.

Buyers standing up agent frameworks now inherit the patch-velocity problem that edge appliances have carried for years. Each new AI-application layer adds internet-facing code that attackers probe as fast as vendors and CISA can list the results, and Langflow is the first such framework to earn a repeat entry.

Deep Analysis

In plain English

Langflow is free, open-source software that lets developers build AI chatbot and agent pipelines by dragging and connecting blocks instead of writing code from scratch. Because it often stores passwords and access keys for other services it connects to, a security flaw in Langflow can give an attacker access well beyond Langflow itself. On 21 July, CISA added a second Langflow flaw, CVE-2026-0770, to its list of vulnerabilities under active attack, giving US federal agencies until 24 July to fix it. This is the second Langflow flaw added to that list within two months, a fast repeat for one piece of software.

Deep Analysis
Root Causes

Langflow's structural exposure comes from its role as an orchestration layer: because it stores API tokens and credentials for every downstream service a pipeline connects to, a single flaw gives an attacker a pivot point reaching every service the pipeline touches, well beyond the Langflow instance itself.

A second KEV entry within two months suggests the codebase's attack surface, built for rapid feature delivery in a fast-moving open-source AI tooling project, has not yet had the multiple rounds of hardening review that longer-established infrastructure software has undergone.

Escalation

No threat actor has yet been publicly attributed to CVE-2026-0770, unlike Langflow's first KEV entry which was tied to MuddyWater.

What could happen next?
  • Risk

    Langflow's second KEV entry in two months marks it as a recurring exploitation surface rather than a one-off flaw, raising the odds of a third entry if the underlying hardening gap is not addressed.

  • Consequence

    Organisations running Langflow now face two separate federal-deadline patch cycles within two months, straining the same patching resources used for other KEV entries in this fortnight's batch.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

CISA· 24 Jul 2026
Read original
Causes and effects
This Event
Langflow hits KEV a second time
A second exploited-vulnerabilities entry in two months puts AI-agent-orchestration software on the recurring-exploitation trajectory long familiar from edge appliances.
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.