Vendor
Langflow
As of , 5 Langflow vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2026-0770.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-0770Inclusion of Functionality from Untrusted Control Sphere | Langflow Langflow | Patch nowForensic triage required by CISA; Metasploit module | 0.63 | ||
| 2 | CVE-2026-55255Authorization Bypass Through User-Controlled Key | Langflow Langflow | Patch nowForensic triage required by CISA | 0.01 | ||
| 3 | CVE-2025-3248Missing Authentication | Langflow Langflow | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 4 | CVE-2026-33017Code Injection | Langflow Langflow | Patch this weekMetasploit module | 0.25 | ||
| 5 | CVE-2025-34291Origin Validation Error | Langflow Langflow | Patch this weekEPSS 0.93 | 0.93 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2025 | 1 |
| 2026 | 4 |