CVE-2026-7873Disclosure(langflow / langflow)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for langflow langflow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.

3.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-06)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-09: 1Mentions · 2026-09-06: 2PoC Mentioned / Linked · 2026-09-06: 1Exploit Tool / Code · 2026-09-06: 1Technical Details · 2026-07-09: 107-0909-06
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-091
Disclosure1
2026-09-062
General1PoC1
Full discourse3 posts
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-4aQyqA0 [CRITICAL/PoC] Linked: CVE-2026-7873 POC-CVE-2026-7873 🔗 https://exploitgrid.net/exploits/fb1579f2-d4bc-4b8f-8dbb-f12b78e7c0db

    Post summary

    The post announces a proof‑of‑concept (PoC) for CVE‑2026‑7873 and links to an exploit grid entry that likely contains exploit code.

    1000051
    40 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-27941 CVE-2026-31852 CVE-2026-56290 CVE-2026-7873 CVE-2023-42793 ..🧵👇

    Post summary

    The post is a brief enumeration of CVEs without additional context, leaving the nature of the threats ambiguous.

    1000049
    40 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Langflowに重大な脆弱性6件、IBMが発見-未認証RCEからAPIキーの越境流用まで広範囲に影響(CVE-2026-10134、CVE-2026-7803、CVE-2026-7871、CVE-2026-7873、CVE-2026-10140、CVE-2026-7663) https://rocket-boys.co.jp/security-measures-lab/langflow-unauthenticated-rce-cve-2026-10134/ #セキュリティ対策Lab #security #securitynews

    Post summary

    IBM reported six critical vulnerabilities in Langflow, ranging from unauthenticated remote code execution to cross‑boundary API key misuse. The post includes CVE identifiers and links to more information.

    00000158
    462 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more