HomeSecurityCISA: Langflow and Trend Micro vulnerabilities on the KEV list

CISA: Langflow and Trend Micro vulnerabilities on KEV list

CISA has added two critical security vulnerabilities, affecting Langflow and Trend Micro Apex One , to its Known Exploited Vulnerabilities (KEV) list. The two vulnerabilities are considered particularly dangerous as they could allow attackers to gain complete control over target systems.

CISA: Langflow and Trend Micro vulnerabilities on KEV list

The first vulnerability added to the list is CVE-2025-34291 with a CVSS score of 9.4. This is an “origin validation error” vulnerability in Langflow and could allow an attacker to execute arbitrary code and achieve a complete system compromise.

The second vulnerability, CVE-2026-34926 with a CVSS score of 6.7, is a directory traversal vulnerability in on-premise versions of Trend Micro Apex One that could allow a authenticated local attacker to modify key tables on the server to inject malicious code.

See also: Trend Micro: Critical vulnerabilities in Apex One

According to a report by Obsidian Security published in December 2025, CVE-2025-34291 exploits three combined vulnerabilities: overly Permissive CORS , lack of cross-site request forgery (CSRF) protection , and an endpoint that allows code execution by design .

The impact is severe, as successful exploitation not only compromises the Langflow but also exposes all sensitive access tokens and API keys stored in the workspace. This can compromise all embedded downstream services in cloud and SaaS environments, significantly extending the scope of the attack beyond the initial target system.

CISA: Langflow and Trend Micro vulnerabilities on KEV list

Active exploitation by an Iranian group and the Langflow ecosystem

In a report published in March 2026, Ctrl-Alt-Intel reported that the vulnerability had been used by the Iranian hacking group MuddyWater to gain initial access to target networks. MuddyWater is known for its attacks against government and corporate targets. The group’s use of this vulnerability demonstrates the strategic value that APT groups place on exploiting artificial intelligence platforms as an entry point into corporate networks.

Langflow has been hit with multiple security vulnerabilities in recent months, including CVE-2025-3248 and CVE-2026-33017 , which were also added to the KEV list earlier this year. This pattern suggests that AI workflow platforms are becoming increasingly attractive targets for cybercriminals, especially when exposed online without adequate protection.

See also: CISA: Warns of vulnerability in Trend Micro Apex One

Regarding CVE-2026-34926, Trend Micro said it has observed at least one instance of an attempted exploitation of the vulnerability. The company clarified that the vulnerability is only exploitable in the on-premise version of Apex One , and a potential attacker would need to have access to the Apex One Server and have already obtained administrative credentials through some other method.

CISA KEV list of Langflow and Trend Micro Apex One vulnerabilities

Despite these limitations, exploiting such a vulnerability in a centralized security management system could allow attackers to disable protections, deploy malware on a large scale, or use the security platform as a trusted internal foothold.

Technical protection advice and immediate measures

Security experts recommend specific measures to protect against these vulnerabilities. For Langflow, organizations should avoid exposing the platform to the internet unless absolutely necessary, remove or tightly control public flows, and disable convenience features such as auto-login. Additionally, it is recommended to review logs for unusual flow creation, suspicious build requests, unexpected code execution, and outbound connections from Langflow hosts. Isolating AI workflow servers from production systems and sensitive credentials is also critical.

See also: Exploiting RCE vulnerability in Trend Micro Apex One

For Trend Micro Apex One , administrators should closely follow Trend Micro ’s emergency guidelines , limit access to the management console to a small set of trusted administrators, and ensure that endpoint protection servers are not widely exposed to the internet. Monitoring for unauthorized policy changes, unusual agent deployments, log deletions, or unexpected administrative sessions is also crucial.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Due to active exploitation, federal agencies ( FCEB ) are required to implement the necessary fixes by June 4, 2026 to secure their networks. Being added to the KEV list means that the vulnerabilities are considered an immediate risk and require urgent remediation. While this obligation applies to U.S. federal agencies, KEV listings are often treated as urgent indicators for all agencies worldwide.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS