CISA added an unauthenticated remote code execution (RCE) flaw in Langflow, an open source layer bundled in IBM's agentic AI stack, to its Known Exploited Vulnerabilities (KEV) catalog, with an Aug.
IBM customers running the company's agentic AI platform should patch today. CISA has added the underlying unauthenticated remote code execution flaw, tracked as CVE-2026-9198, to its Known Exploited Vulnerabilities catalog with an August 7 deadline for federal agencies. BleepingComputer, citing KEVIntel, reports 220+ exploitation attempts from 64 IP addresses since June 27. Those are live attacks, not just scans.
IBM Security Bulletin node/7278927 is titled "Security Bulletin: Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation." SentinelOne's profile of CVE-2026-9198 ties the advisory to a Langflow RCE, and The Register first reported the story on August 5 as active attacks on IBM's agentic AI platform requiring immediate patching.
Langflow itself is an open-source project, not a native IBM product. The NVD entry for CVE-2026-9198 profiles the underlying RCE and the unauthenticated trigger path.
BleepingComputer's Langflow coverage lists the CISA order and notes that two earlier Langflow flaws, CVE-2026-33017 and CVE-2026-55255, were also exploited before this one. The KEV catalog addition is logged by Windows Forum alongside N-central and Tomcat under the same August 7 deadline.
Operators running the platform should confirm which surface carries the vulnerable Langflow build and whether the CVE their bulletin tracks is the one CISA KEV-listed.