3 vulnerabilities across 1 product scored HIGH or above on October 07, 2026.

  • ๐Ÿ”ด CRITICAL: 1
  • ๐ŸŸ  HIGH: 2

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) โ€” F1: exploitable โ†’ functional, AAS: 10.9 โ†’ 13.4 (HIGH โ†’ CRITICAL). Originally in 2026-09-30 bulletin.

๐Ÿ”ด [CRITICAL] ibm/langflow_oss

3 CVEs | CVSS 3.1: 9.8 | AAS 12.4

  • cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:* (>= 1.0.0, < 1.12.3)
  • cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:* (>= 1.0.0)

IBM Langflow OSS versions 1.0.0 through 1.12.2 is affected by three vulnerabilities, including at least one critical-severity remote code execution flaw (CVSS 9.8) stemming from improper neutralization of special elements in OS commands. Proof-of-concept exploit code is available, increasing the likelihood of active exploitation. Organizations running Langflow OSS in any capacity, particularly internet-facing deployments, should treat this as an urgent priority.

Security teams should review the IBM advisory at https://www.ibm.com/support/pages/node/7290694 and upgrade to a patched version immediately. Given the critical severity and public exploit availability, any delay in remediation leaves environments exposed to unauthenticated remote code execution.

Vendor Advisory