Tag
critical
advisory
IBM Langflow OSS Code Injection Vulnerability in ToolGuard (CVE-2026-9135)
3 TTPs 1 CVEAn authenticated attacker can exploit CVE-2026-9135, a code injection vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.2, to bypass security controls and achieve arbitrary Python code execution on the backend through unvalidated dynamic CodeInput fields in the ToolGuard integration, potentially escalating privileges via cross-tenant flow manipulation.
Langflow OSS
code-injection
vulnerability
rce
langflow
hard-coded-credentials
ibm
3t
1c
critical
advisory
CVE-2026-14807: PROG MIS ERP App Hard-coded Credentials Vulnerability
3 TTPs 1 CVEAn unauthenticated remote attacker can exploit a Use of Hard-coded Credentials vulnerability (CWE-798) in the ERP App developed by PROG MIS, allowing the attacker to log in to view application code and obtain database account and password information, leading to high impact on confidentiality, integrity, and availability.
ERP App
hard-coded-credentials
erp
web-application
vulnerability
3t
1c