3 vulnerabilities across 1 product scored HIGH or above on October 07, 2026.
- ๐ด CRITICAL: 1
- ๐ HIGH: 2
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-76504 (cisco/catalyst_sd-wan_manager) โ F1: exploitable โ functional, AAS: 10.9 โ 13.4 (HIGH โ CRITICAL). Originally in 2026-09-30 bulletin.
๐ด [CRITICAL] ibm/langflow_oss
3 CVEs | CVSS 3.1: 9.8 | AAS 12.4
cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:*(>= 1.0.0, < 1.12.3)cpe:2.3:a:ibm:langflow_oss:*:*:*:*:*:*:*:*(>= 1.0.0)
IBM Langflow OSS versions 1.0.0 through 1.12.2 is affected by three vulnerabilities, including at least one critical-severity remote code execution flaw (CVSS 9.8) stemming from improper neutralization of special elements in OS commands. Proof-of-concept exploit code is available, increasing the likelihood of active exploitation. Organizations running Langflow OSS in any capacity, particularly internet-facing deployments, should treat this as an urgent priority.
Security teams should review the IBM advisory at https://www.ibm.com/support/pages/node/7290694 and upgrade to a patched version immediately. Given the critical severity and public exploit availability, any delay in remediation leaves environments exposed to unauthenticated remote code execution.
- ๐ด CVE-2026-93674 (CVSS 3.1: 9.8)
- ๐ CVE-2026-104334 (CVSS 3.1: 9.8)
- ๐ CVE-2026-93675 (CVSS 3.1: 8.8)