The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. government agencies to patch a critical, actively exploited remote code execution (RCE) vulnerability in the Langflow visual framework for building AI agents. The flaw, identified as CVE-2026-0770, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on Tuesday, July 22, 2026, with federal agencies mandated to secure affected systems by Friday, in accordance with Binding Operational Directive (BOD) 26-04.
Trend Micro researchers discovered and reported CVE-2026-0770, describing it as a critical security flaw that allows unauthenticated attackers to achieve remote code execution as root with low complexity. The vulnerability resides in the handling of the `exec_globals` parameter within the `validate` endpoint, stemming from the inclusion of a resource from an untrusted control sphere. This allows an attacker to execute arbitrary code with root privileges.
Vulnerability intelligence firm KEVIntel first detected in-the-wild exploitation of CVE-2026-0770 on June 27. Since then, KEVIntel has recorded over 220 exploitation attempts originating from 64 distinct IP addresses. Analysis of these attacks indicates that malicious activity extends beyond simple vulnerability checks. Observed payloads include attempts to deploy malware and exfiltrate sensitive information such as AWS credentials, environment variables, and container metadata. Organizations operating Langflow are advised to review historical requests to `/api/v1/validate/code`, investigate host activity, restrict access to the validation functionality, and rotate any exposed credentials if successful execution cannot be definitively ruled out.
CISA emphasized that vulnerabilities of this nature are frequently leveraged by malicious cyber actors and pose significant risks to federal enterprises. Agencies are responsible for assessing the internet exposure of their assets and ensuring compliance with BOD 26-04 patching guidelines.
This is not the first time CISA has flagged Langflow vulnerabilities for active exploitation. The agency previously identified a missing authentication security issue (CVE-2025-3248) in May 2025, a code injection vulnerability (CVE-2026-33017) in March 2026, and an Insecure Direct Object Reference (IDOR) flaw (CVE-2026-55255) earlier in July. CISA also confirmed that CVE-2025-3248 is being exploited in ransomware attacks, with reports from cloud security company Sysdig indicating its use by the JadePuffer ransomware gang to dump Langflow PostgreSQL databases.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.