CyberMax
Home › Exploited CVEs

Langflow known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 Langflow CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-07-21), and 1 are known to be used in ransomware campaigns.

Langflow CVEs added to CISA KEV per year
2025: 1202512026: 420264

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Langflow products

Langflow (5).

All Langflow CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-0770LangflowInclusion of Functionality from Untrusted Control Sphere2026-07-212026-07-2463.8%–
CVE-2026-55255LangflowAuthorization Bypass Through User-Controlled Key2026-07-072026-07-100.9%–
CVE-2025-34291LangflowOrigin Validation Error2026-05-212026-06-0492.8%–
CVE-2026-33017LangflowCode Injection2026-03-252026-04-0824.8%–
CVE-2025-3248LangflowMissing Authentication2025-05-052025-05-26100.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors