CISA KEV Intelligence Briefing — 2026-03-26
The Cybersecurity and Infrastructure Security Agency (CISA) has added 1 new vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog. These represent active exploitation in the wild and require immediate attention from enterprise security teams.
Critical CVEs Added
- CVE-2026-33017 — Langflow Code Injection Vulnerability (Langflow / Langflow) Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due: 2026-04-08
FLLC Recommended Actions
- Patch immediately — Apply vendor-provided patches for all listed products.
- Verify exposure — Audit your asset inventory against affected vendors and products.
- Enable threat detection — Ensure your EDR and SIEM are tuned for these CVE indicators.
- Review CISA deadlines — Federal agencies have binding operational directives; enterprises should adopt equivalent urgency.
Resources
This briefing is auto-generated by the FLLC CVE Monitor pipeline. All data sourced from CISA KEV.