Skip to content

Products › Server applications and development

Server applications and development

AI and automation

AI, large language model and workflow automation platforms, recent arrivals in the catalog.

For example: Langflow, LiteLLM, MLflow, n8n.

Category RSS feed

Pace of additions

Number of “AI and automation” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20250
Oct 9, 2025 to Nov 7, 20250
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20260
Feb 6, 2026 to Mar 7, 20260
Mar 8, 2026 to Apr 6, 20262
Apr 7, 2026 to May 6, 20261
May 7, 2026 to Jun 5, 20262
Jun 6, 2026 to Jul 5, 20261
Jul 6, 2026 to Aug 4, 20263
Aug 5, 2026 to Sep 3, 20264
Sep 4, 2026 to Oct 3, 2026 (in progress)0

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Apache 2 vulnerabilities
  • BerriAI 3 vulnerabilities · 3 in the last 12 months
  • Kestra 1 vulnerability · 1 in the last 12 months
  • Langflow 6 vulnerabilities · 5 in the last 12 months
  • Marimo 1 vulnerability · 1 in the last 12 months
  • MLflow 1 vulnerability · 1 in the last 12 months
  • n8n 1 vulnerability · 1 in the last 12 months
  • Ray 1 vulnerability · 1 in the last 12 months

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    Kestra OSSCVE-2026-49869

    Kestra OSS OS Command Injection Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 10.0critical

    Added Sep 2, 2026

  2. Rank 2

    LangflowCVE-2026-9198

    IBM Langflow Code Injection Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Aug 4, 2026

  3. Rank 3

    LangflowCVE-2026-0770

    Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 21, 2026

  4. Rank 4

    BerriAI LiteLLMCVE-2026-42208

    BerriAI LiteLLM SQL Injection Vulnerability

    CVSS severity 9.8critical

    Added May 8, 2026

  5. Rank 5

    MarimoCVE-2026-39987

    Marimo Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Apr 23, 2026

  6. Rank 6

    LangflowCVE-2026-33017

    Langflow Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Mar 25, 2026

  7. Rank 7

    MLflowCVE-2026-64849

    MLflow Server-Side Request Forgery Vulnerability

    CVSS severity 9.3critical

    Added Aug 19, 2026

  8. Rank 8

    RayCVE-2025-62593

    Ray-Project Ray Code Injection Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 8.8high

    Added Aug 17, 2026

  9. Rank 9

    BerriAI LiteLLMCVE-2026-42271

    BerriAI LiteLLM Command Injection Vulnerability

    CVSS severity 8.8high

    Added Jun 8, 2026

  10. Rank 10

    LangflowCVE-2025-34291

    Langflow Origin Validation Error Vulnerability

    CVSS severity 8.8high

    Added May 21, 2026

Show 6 more vulnerabilities
  1. Rank 11

    n8nCVE-2025-68613

    n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

    CVSS severity 8.8high

    Added Mar 11, 2026

  2. Rank 12

    LangflowCVE-2026-55255

    Langflow Authorization Bypass Through User-Controlled Key Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 8.4high

    Added Jul 7, 2026

  3. Rank 13

    BerriAI LiteLLMCVE-2026-59822

    BerriAI LiteLLM Improper Authentication Vulnerability

    CVSS severity 8.2high

    Added Sep 2, 2026

  4. Rank 14

    LangflowCVE-2025-3248

    Langflow Missing Authentication Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added May 5, 2025

  5. Rank 15

    Apache AirflowCVE-2020-13927

    Apache Airflow's Experimental API Authentication Bypass

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Jan 18, 2022

  6. Rank 16

    Apache AirflowCVE-2020-11978

    Apache Airflow Command Injection

    CVE from 2020, added in 2022

    CVSS severity 8.8high

    Added Jan 18, 2022

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.