July 23, 2026
- CVE-2026-0770 — Langflow RCE added to CISA KEV under active exploitation. The critical (CVSS 9.8) unauthenticated RCE in the popular AI-agent-building framework abuses the
exec_globalsparameter in the validation endpoint; CISA ordered federal agencies to patch on an urgent timeline (BleepingComputer). · AI & Model Security