VENDOR

IBM vulnerabilities: CVEs, exploitation and patches

Every IBM CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-12940
    Langflow OSS environment-variable RCE in MCP stdio launcher IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-9205
    Langflow OSS weak key derivation allows remote secret compromise IBM Langflow OSS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-19286
    Langflow OSS A2A endpoint remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-85025
    Langflow OSS unauthenticated code execution via public MCP endpoints IBM Langflow OSS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-79724
    Langflow OSS command injection allows remote OS command execution IBM Langflow OSS ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-81204 CRITICAL 9.8
  7. CVE-2026-17633
    Langflow OSS code injection allows authenticated remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  8. CVE-2026-18729
    Langflow OSS authenticated remote code execution IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  9. CVE-2026-12944
    Langflow OSS remote code execution as root via component imports IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  10. CVE-2026-19295
    Langflow OSS authenticated OS command execution via crafted flow IBM Langflow OSS ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.9
  11. CVE-2026-9198
    Langflow unauthenticated remote code execution IBM Langflow ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
11 CVEs · page 1 of 1