The clock is ticking for federal agencies. CISA added an actively exploited Langflow vulnerability to its Known Exploited Vulnerabilities catalog on Tuesday, giving FCEB agencies until Friday to patch.
The bug is CVE-2026-55255, an Insecure Direct Object Reference flaw in Langflow — the visual framework for building AI agents. It lets authenticated attackers access other users’ flows by sending a crafted request to the /api/v1/responses endpoint with the victim’s UUID.
Sysdig’s Threat Research Team spotted in-the-wild exploitation on June 25. Their assessment? Opportunistic, financially motivated attackers going after compute (botnet/implant) and credentials (LLM/cloud keys). Cheap, repeatable, low-sophistication tooling.
Langflow’s been a target before. CISA added a missing authentication flaw (CVE-2025-3248) to KEV in May 2025, which ransomware gangs later used to dump Langflow’s PostgreSQL databases. Then in March 2026, a code injection bug (CVE-2026-33017) got the same treatment. And attackers have been actively exploiting yet another path traversal vulnerability (CVE-2026-5027) since June to write arbitrary files on exposed servers.
If you’re running Langflow, today’s the day to check your version and patch. Friday’s deadline is for feds, but the attackers aren’t limiting themselves to government networks.
