Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE
A high-severity path traversal vulnerability in Langflow, designated CVE-2026-5027 (CVSS 8.8), is being actively exploited in the wild. Discovered by Tenable, the…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
A high-severity path traversal vulnerability in Langflow, designated CVE-2026-5027 (CVSS 8.8), is being actively exploited in the wild. Discovered by Tenable, the…
An unauthenticated RCE flaw in Langflow, fixed in version 1.9.0. Added to CISA KEV catalog on March 25, 2026.
CVE-2026-21445 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Ivanti, Fortinet, and SAP have released security patches addressing multiple critical vulnerabilities that could lead to arbitrary code execution and information disclosure.Fortinet…
An authentication bypass vulnerability in Ivanti Sentry before versions R10.5.2, R10.6.2, and R10.7.1 allows remote unauthenticated attackers to create arbitrary administrative accounts…
CVE-2023-20118 is a vulnerability in Cisco RV042 routers that may be exploited by the JDY botnet to compromise devices for cyber reconnaissance.
CVE-2022-32548 is a vulnerability in DrayTek Vigor3900 Series routers that may be exploited by the JDY botnet to compromise devices.
CVE-2023-24738 is a vulnerability in Araknis AN-300-RT-4L2W routers that may be exploited by the JDY botnet to compromise devices.
CVE-2021-36260 is a vulnerability in Hikvision products that allows remote code execution. It was exploited in the StrikeShark campaign.
CVE-2025-32433 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…