FR
live
Critical Actively exploited

CVE-2026-0770

Langflow

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

What this means

Weakness
Code from an untrusted source is loaded and executed.
Likelihood
Exploitation is not hypothetical: CISA has observed it in the wild.

What to doTop priority: CISA sets the remediation deadline at 24 July 2026.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
21 July 2026
CVSS
EPSS
56.27% probability of exploitation within 30 days · above 99% of all CVEs
Weakness
CWE-829
CISA due date
24 July 2026 past due
Sources
cisa-kev
References

Type at least two characters.

navigate open esc dismiss