What the September 2026 IBM advisory means for teams running Langflow OSS in production
Vulnerability overview
IBM shipped fixes for twelve vulnerabilities affecting IBM MQ, IBM MQ Appliance and Langflow OSS. The Dutch NCSC summarised them in advisory NCSC-2026-0392 on 23 September 2026. Langflow OSS accounts for several entries, three of which, CVE-2026-79724, CVE-2026-85025 and CVE-2026-81204, carry a CVSS v3 score of 9.8 and need no authentication.
Mechanism and exploitation conditions
The advisory assigns code injection and OS command injection to the Langflow issues. Within the broader set it also flags missing authorization and incorrect authorization. The three unauthenticated issues allow arbitrary code or operating system command execution. The rest of the Langflow entries are rated 8.8 and require an authenticated session.
Impact
For a production deployment the practical consequence is credential exposure. A Langflow service runs flows that authenticate to model providers, datastores and third party APIs. Whoever executes code as that service can read those credentials and reuse them elsewhere.
Affected products and scope
The advisory names the affected products directly and does not publish version ranges. IBM's own bulletins carry the fixed builds, and they should be read before planning the upgrade.
Exposure context
A ZoomEye query for app="Langflow" returned 18,550 matching instances when checked on 23 September 2026. That number counts fingerprinted product assets, not hosts confirmed vulnerable to any of the three CVEs.
Remediation and mitigations
Upgrade to an IBM fixed build and confirm the running version afterwards. Restrict who can reach the service while the rollout is in progress, and separate the Langflow host from the secrets it does not need. Where flows store provider keys in the platform itself, rotate those keys after patching so a pre patch compromise cannot be replayed.
References
- NCSC-NL, advisory NCSC-2026-0392 (23 September 2026): https://advisories.ncsc.nl/advisory?id=NCSC-2026-0392
- IBM security bulletin for the Langflow OSS fixes: https://www.ibm.com/support/pages/node/7284543
- IBM security bulletin for the IBM MQ fixes: https://www.ibm.com/support/pages/node/7286666
Top comments (0)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.