CISA Flags Langflow and Trend Micro Apex One as Actively Exploited — Patch Deadline Set
Two high-severity vulnerabilities spanning an AI workflow platform and a widely deployed enterprise endpoint security suite are now confirmed weapons in live attack campaigns.
Written by OutOfToken AI
May 24, 2026 · 4 min read · Synthesized from reporting by The Hacker News · How this works
The U.S. Cybersecurity and Infrastructure Security Agency moved Thursday to add two actively exploited security flaws to its Known Exploited Vulnerabilities catalog — one targeting Langflow, the open-source AI application builder, and the other hitting Trend Micro's Apex One on-premises endpoint protection platform. Both vulnerabilities carry serious risk profiles and are already being weaponized in the wild, CISA confirmed. Federal civilian agencies face a hard remediation deadline of June 4, 2026, though the threat extends well beyond government networks.
A Critical RCE in the AI Pipeline
CVE-2025-34291 is the more technically alarming of the two, earning a CVSS score of 9.4. Rooted in an origin validation error within Langflow, the flaw enables remote code execution — meaning an unauthenticated attacker who can reach an exposed Langflow instance can potentially execute arbitrary commands on the underlying host. Langflow has gained significant traction among developers building agentic AI workflows and LLM-powered pipelines, making its attack surface broader than many niche tools. The fact that Langflow deployments are frequently internet-facing — spun up rapidly by engineering teams experimenting with AI orchestration — compounds the exposure considerably. CISA's confirmation of active exploitation means proof-of-concept has graduated to operational threat.
Directory Traversal Hits Trend Micro's Enterprise Defenses
The second entry, CVE-2026-34926, targets Trend Micro Apex One's on-premises deployment and is classified as a directory traversal vulnerability. Directory traversal flaws allow attackers to access files and directories stored outside the intended web root folder, potentially exposing sensitive configuration data, credentials, or system files. In the context of an endpoint security platform — software that by design holds privileged access across managed machines — the blast radius of such exploitation is disproportionately severe. Apex One is deployed extensively across enterprise environments in sectors ranging from financial services to healthcare, and on-premises installations often lag behind cloud-managed counterparts in patch velocity, precisely the kind of gap threat actors have learned to exploit.
"CVE-2025-34291 scores a 9.4 CVSS — a near-maximum severity rating for a flaw that lets attackers execute code remotely on AI infrastructure with no authentication required."
KEV Catalog as Operational Intelligence
CISA's KEV catalog isn't a theoretical risk register — entries require confirmed evidence of active exploitation before they're added, making each listing an actionable intelligence signal. The catalog now carries hundreds of entries spanning products from virtually every major vendor, but additions involving security software itself, as with Apex One, carry a distinct irony and urgency. Organizations running these tools may feel insulated from risk by virtue of their defensive posture, but unpatched security software is routinely targeted because attackers understand it operates with elevated system privileges. For Langflow users, the calculus is different but equally pressing: AI development tooling has historically moved fast on features and slow on security hardening, and CVE-2025-34291 is a direct consequence of that imbalance.
Both Trend Micro and the Langflow maintainers are expected to have patches available, and organizations should treat the June 4, 2026 federal deadline as a ceiling, not a target. Threat actors don't wait for compliance windows. As AI-native tooling becomes embedded in production infrastructure and enterprise security platforms remain perennially under-patched, CISA's dual listing is a reminder that the attack surface is expanding faster than most security teams can track — and that even the tools meant to provide protection can become the point of entry.
Editorial Note
CISA's KEV catalog is an authoritative, publicly verifiable source for actively exploited vulnerabilities. The Hacker News is a reputable cybersecurity publication with strong track record for accuracy on vulnerability disclosures. The specific details (CVE numbers, CVSS scores, agency attribution) are readily verifiable through official CISA channels.
Claim Tracker
AI-assessed
Article cites CISA action but specific date confirmation would require CISA website verification
Specific CVSS scores are verifiable against NVD but not independently confirmed in this article
Technical characterization plausible but requires CVE database verification
CISA does set specific deadlines but this particular date would require CISA directive verification
Claims 'confirmed' by CISA but no exploitation data samples or incident reports provided in article
Ask AI about this story
// discussion
sign in to join the discussion
