VENDOR
IBM vulnerabilities: CVEs, exploitation and patches
Every IBM CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-12940
Langflow OSS environment-variable RCE in MCP stdio launcherCRITICAL 9.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-9205
Langflow OSS weak key derivation allows remote secret compromiseCRITICAL 9.8
- PATCH AVAILABLE
-
CVE-2026-19286
Langflow OSS A2A endpoint remote code executionCRITICAL 9.8
- PoC PUBLIC
- PATCH AVAILABLE
- CVE-2026-85025 CRITICAL 9.8
- CVE-2026-79724 CRITICAL 9.8
- CVE-2026-81204 CRITICAL 9.8
-
CVE-2026-17633
Langflow OSS code injection allows authenticated remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-18729
Langflow OSS authenticated remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-12944
Langflow OSS remote code execution as root via component importsCRITICAL 9.6
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-19295
Langflow OSS authenticated OS command execution via crafted flowCRITICAL 9.9
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-9198
Langflow unauthenticated remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
11 CVEs · page 1 of 1