An AI app-builder is being mass-exploited — 650 attempts from 41 countries against one Langflow bug
2026-08-09AI
CVE-2026-9198 gives unauthenticated remote code execution on default Langflow deployments, and it was patched in July. Telemetry recorded 650 exploitation attempts from 244 IPs before CISA added it to the KEV catalog on 5 August.