<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/langflow.xml</id>
  <title>Exploit Radar: exploited Langflow vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for Langflow products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/langflow.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/langflow/"/>
  <updated>2026-08-04T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-9198/</id>
    <title>CVE-2026-9198 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-9198/"/>
    <updated>2026-08-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on August 4, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-0770/</id>
    <title>CVE-2026-0770 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-0770/"/>
    <updated>2026-07-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on July 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-55255/</id>
    <title>CVE-2026-55255 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-55255/"/>
    <updated>2026-07-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on July 7, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-34291/</id>
    <title>CVE-2025-34291 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-34291/"/>
    <updated>2026-05-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. For cloud services, follow the guidance from Langflow. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on May 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-33017/</id>
    <title>CVE-2026-33017 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-33017/"/>
    <updated>2026-03-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. For cloud services, follow the guidance from Langflow. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-3248/</id>
    <title>CVE-2025-3248 — Langflow</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-3248/"/>
    <updated>2025-05-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Langflow; if none are available, stop using the product. For cloud services, follow the guidance from Langflow. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 5, 2025.</summary>
  </entry>
</feed>
