TL;DR: In early August 2026, CISA added Langflow's CVE-2026-9198, a CVSS 9.8 flaw that lets an unauthenticated attacker achieve full remote code execution on default deployments of the popular AI application-building platform, to its Known Exploited Vulnerabilities catalog, alongside an Apache Tomcat flaw and the N-able N-central issues. The pattern behind the headline matters more than any single CVE: the AI experiments, dashboards, and web tools that teams spin up on their own, often without IT's knowledge, are exactly the kind of internet-facing software that ends up on a must-patch list with no one assigned to patch it. For a North Carolina small business, the lesson is that you cannot secure what you do not know you are running.
Key takeaway: A weekend AI experiment left running on a public server is not a science project anymore, it is attack surface. If nobody owns an inventory of what your business is running, attackers will build one for you.
Not sure what internet-facing tools your business is actually running? Contact Preferred Data Corporation at (336) 886-3282 for an asset-inventory and vulnerability review. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.
What is the Langflow vulnerability CVE-2026-9198?
CVE-2026-9198 is a critical remote code execution flaw in Langflow, an open-source platform for building AI applications, that allows an unauthenticated attacker to run arbitrary code on default deployments. Per The Hacker News, it carries a CVSS score of 9.8, was addressed in Langflow version 1.10.1, and was added to CISA's Known Exploited Vulnerabilities catalog in August 2026.
The facts that make this urgent:
- CVSS 9.8, unauthenticated, full RCE. There is no higher-severity combination. An attacker who can reach a vulnerable Langflow instance can take it over without credentials.
- It affects default deployments. This is not a misconfiguration edge case, it is the out-of-the-box state, which dramatically widens the pool of exposed instances.
- It is on the CISA KEV catalog with a federal remediation deadline of August 7, 2026, which means it is confirmed to be exploited and should jump to the front of any patch queue.
Langflow is exactly the kind of tool a curious developer or an eager team stands up to prototype an AI workflow. That is the point: the risk is not that Langflow is uniquely bad, it is that these tools proliferate faster than anyone tracks them.
Why are self-hosted AI and web tools such a big risk?
Self-hosted tools are risky because they are often deployed outside IT's visibility, exposed to the internet, and then forgotten, which means no one is watching for or applying the critical patches they need. The same CISA update that flagged Langflow also flagged a widely deployed Apache Tomcat flaw, CVE-2026-34486, underscoring that this is a pattern across the web software small businesses quietly run.
Four factors compound the danger:
- They are invisible to IT. A tool stood up by a team without going through IT never enters the asset inventory, so it never enters the patch schedule either.
- They are internet-facing by default. Many are deployed on cloud instances reachable from anywhere, turning a local experiment into a global attack surface.
- They run on stacks that also need patching. The Tomcat CVE is a reminder that the web server or framework underneath a tool is its own vulnerability, fixed in versions 11.0.21, 10.1.54, and 9.0.117 back in April 2026 yet still exploited where unpatched.
- Exploits arrive fast. Once a flaw like a 9.8 RCE is public, proof-of-concept code and mass scanning follow within days, and unmanaged instances are the easiest targets.
Key takeaway: The dangerous software is rarely the tool you carefully chose and manage. It is the one someone spun up, exposed to the internet, and stopped thinking about. Visibility is the whole game.
Want to find the forgotten servers before an attacker does? Call Preferred Data at (336) 886-3282 or explore our Managed IT and Cybersecurity services.
How does a small business get control of its AI and software sprawl?
You get control by knowing what you run, deciding what is sanctioned, and making sure everything that stays gets patched and monitored, which is a governance problem as much as a technical one. The goal is not to ban experimentation, it is to make sure nothing lives on your network without an owner.
A practical path to control:
- Build and maintain an asset inventory. You cannot patch or monitor what you have not catalogued. Discovery of internet-facing systems is step one.
- Set a lightweight AI and software policy. Give teams a sanctioned way to request and stand up tools, so innovation happens inside guardrails instead of in the shadows.
- Put unmanaged tools under management, or retire them. Anything that stays should be patched on a schedule, monitored, and secured behind proper authentication, never exposed to the open internet without cause.
- Prioritize actively exploited flaws. Vulnerabilities in CISA's KEV catalog are confirmed to be under attack and belong at the front of the queue.
For a North Carolina small business without a dedicated security team, a managed IT partner supplies exactly the continuous inventory, patching, and monitoring that keeps a Langflow-style tool from becoming an open door.
Unmanaged tool sprawl versus a governed environment
| Factor | Tool sprawl | Governed environment |
|---|---|---|
| Asset inventory | None or stale | Maintained and discovered continuously |
| New tools | Stood up in the shadows | Requested through a sanctioned path |
| Internet exposure | Common and unnoticed | Minimized and justified |
| Patch responsibility | Unassigned | Owned and scheduled |
| KEV flaws | Missed for weeks | Prioritized on deadline |
| Attack surface | Growing, invisible | Known and shrinking |
Ready to know exactly what your business runs? Call (336) 886-3282 or learn about our Managed IT Services.
Does this mean my business should avoid AI tools?
No. The answer is to adopt AI tools deliberately and manage them, not to avoid them and fall behind. Langflow and platforms like it deliver real value, and the problem in this incident is not AI, it is ungoverned deployment. Businesses that experiment with AI inside a managed, patched, monitored environment get the upside without becoming the next easy target.
Three principles keep AI adoption safe:
- Sanctioned beats shadow. Give teams an approved way to build with AI, and they will not resort to unmanaged instances.
- Managed beats forgotten. Any tool worth keeping is worth patching and monitoring, which is a solved problem when someone owns it.
- Inventoried beats invisible. The single most protective habit is simply knowing, and continually rediscovering, what you are running.
Deliberate adoption is how a small business gets the productivity of modern AI tools without inheriting the risk of the ones nobody is watching.
How does Preferred Data secure NC businesses against unmanaged software risk?
Preferred Data Corporation has managed technology for North Carolina businesses since 1987, and we specialize in turning invisible, unmanaged software into a known, patched, monitored environment. Our Managed IT and Cybersecurity services maintain a continuous asset inventory, discover internet-facing systems, prioritize actively exploited vulnerabilities from CISA's KEV catalog, and help you adopt AI tools through AI Transformation in a governed way that captures the value without the exposure.
Because we are local, on-site within 200 miles of High Point, we can work directly with your teams to bring shadow tools into the light and build a practical policy that supports innovation instead of blocking it.
Get an asset-inventory and vulnerability review. Contact Preferred Data Corporation at (336) 886-3282. We deliver Managed IT, Cybersecurity, and AI Transformation for small businesses and manufacturers across the Piedmont Triad. Serving the region since 1987, BBB A+ rated.
Frequently Asked Questions
What is CVE-2026-9198?
CVE-2026-9198 is a critical remote code execution vulnerability in Langflow, an open-source AI application-building platform. It carries a CVSS score of 9.8, lets an unauthenticated attacker run arbitrary code on default deployments, was fixed in Langflow version 1.10.1, and was added to CISA's Known Exploited Vulnerabilities catalog in August 2026 with a federal remediation deadline of August 7.
Is my business at risk if a team uses Langflow?
You are at risk if anyone in your business is running a Langflow instance on a vulnerable version, especially one reachable from the internet. Because the flaw affects default deployments and requires no authentication, an exposed instance can be taken over remotely. Confirm whether Langflow is running anywhere in your environment, update it to at least version 1.10.1, and restrict its access.
Why is self-hosted software so often a security problem?
Because it is frequently deployed outside IT's visibility, exposed to the internet, and then left unpatched. A tool that never enters the asset inventory never enters the patch schedule, so critical fixes go unapplied. Attackers scan the internet for exactly these forgotten, unmanaged instances.
What is the CISA Known Exploited Vulnerabilities catalog?
It is a list CISA maintains of vulnerabilities confirmed to be actively exploited in the wild. Federal agencies must remediate listed flaws by set deadlines, and the catalog is a strong signal for every organization about which vulnerabilities to patch first. Langflow's CVE-2026-9198 and an Apache Tomcat flaw were both added in August 2026.
Should a small business stop using AI tools to stay safe?
No. The risk in incidents like this comes from ungoverned deployment, not from AI itself. A better approach is to adopt AI tools deliberately, through a sanctioned path, and manage them with patching and monitoring. That captures the productivity benefits while keeping the tools from becoming an unwatched attack surface.
How do I find unmanaged software on my network?
Through asset discovery and a maintained inventory, ideally run continuously rather than as a one-time audit. A managed IT provider can scan for internet-facing systems, catalog what is running, and flag anything unpatched or exposed. Knowing what you run is the prerequisite for securing it.