The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to prioritize patching a critical authentication bypass vulnerability within the Langflow AI agent framework. This directive comes as the flaw is reportedly being actively exploited.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies prioritize patching a critical authentication bypass vulnerability affecting the Langflow visual framework. The directive, issued as Binding Operational Directive (BOD) 26-04, requires agencies to secure their systems by Friday.
The vulnerability, identified as CVE-2026-55255, is an Insecure Direct Object Reference (IDOR) flaw. It allows threat actors who have already gained some level of authentication to access other users' saved AI flows. This is achieved by sending a specially crafted request to the /api/v1/responses endpoint, including the target user's flow identifier.
Exploiting CVE-2026-55255 not only grants access to other users' workflows but also enables attackers to steal sensitive data processed by those flows and consume system resources. Sysdig's Threat Research Team (TRT) reported observing exploitation of this vulnerability in the wild as early as June 25.
According to Sysdig researchers, the attackers' objectives were code execution and the delivery of second-stage implants, such as loaders or droppers. They characterized the threat actor as opportunistic and financially motivated, seeking to monetize compromised AI hosts through their compute power (for botnets or implants) and by stealing credentials, including those for large language models and cloud services. The researchers noted that the tooling used was low-sophistication and repeatable.
CISA added CVE-2026-55255 to its Known Exploited Vulnerabilities (KEV) Catalog on Tuesday. The agency emphasized that vulnerabilities of this nature are common attack vectors posing significant risks to federal networks. Agencies are responsible for assessing the internet exposure of their assets and adhering to the patching guidelines outlined in BOD 26-04.
This is not the first time Langflow has been flagged by CISA. In May 2025, the agency added a missing authentication vulnerability (CVE-2025-3248) to its KEV catalog, linking it to ransomware operations that used it to extract data from Langflow's PostgreSQL database. More recently, in March 2026, CISA highlighted a code injection vulnerability (CVE-2026-33017) in the framework.
Furthermore, security researcher Caitlin Condon of VulnCheck reported that a high-severity path traversal vulnerability in Langflow (CVE-2026-5027) has been actively exploited since June. Attackers have leveraged this flaw to write arbitrary files onto exposed servers. Langflow is a popular tool for AI development, providing a drag-and-drop interface for creating AI agent pipelines and a REST API for programmatic execution, making it an attractive target for malicious actors.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed