CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-33017 Langflow Code Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational ...
Steelman: CISA has identified a new vulnerability, CVE-2026-33017, which is being actively exploited by malicious cyber actors. This poses significant risks to federal networks and has prompted the agency to add it to their Known Exploited Vulnerabilities (KEV) Catalog. Binding Operational Directive (BOD) 22-01 requires FCEB agencies to remediate identified vulnerabilities by the due date, and CISA strongly urges all organizations to prioritize timely remediation of KEV Catalog vulnerabilities a...
