CISA's KEV List Just Picked Up Langflow and Apex One — Both Already Being Hit

Two flaws, one AI workflow tool and one veteran endpoint suite, now carry a federal patch deadline because attackers got there first.

ThreatVectr Newsdesk· 2 min read
CISA's KEV List Just Picked Up Langflow and Apex One — Both Already Being Hit
Share

Getting added to CISA's Known Exploited Vulnerabilities catalog is the cybersecurity equivalent of your name showing up on a wanted poster — it means somebody, somewhere, has already pulled the trigger. On Thursday, CISA added two more entries: an origin validation bug in Langflow tracked as CVE-2025-34291 (CVSS 9.4), and a separate flaw in Trend Micro Apex One. Both are being exploited in the wild, and federal civilian agencies now have a hard clock to patch.

Langflow is the part that should make people sit up. It's a popular open-source builder for stitching together LLM workflows (think drag-and-drop plumbing for AI agents), and origin validation errors at CVSS 9.4 typically mean an attacker on the network can talk to the service as if they belong there. That is a fast lane to code execution on a box that, by design, holds API keys to OpenAI, Anthropic, vector databases, and whatever else the team plugged in.

This is the second Langflow bug on the KEV in a matter of months. The earlier one, CVE-2025-3248, was a missing-authentication RCE that botnet operators jumped on almost immediately.

And that pattern matters.

AI tooling is shipping at startup speed but landing in enterprise networks at enterprise scale, said more than one incident responder I've spoken to this year. The threat actors hunting these surfaces aren't waiting for the security model to mature.

The Apex One half of the announcement (Trend Micro's flagship endpoint protection product) is the more familiar story. Endpoint agents run as SYSTEM, talk to a management console, and sit on every workstation in the building — which is exactly why attackers keep finding ways in through them. Trend Micro disclosed a cluster of Apex One Management Console flaws earlier this autumn, including command injection issues the company confirmed were being abused before a patch shipped. Admins should be on the fixed builds already; if you're not, KEV inclusion means you're now out of excuses.

Federal agencies have 21 days under Binding Operational Directive 22-01 to remediate KEV entries, but the private sector should treat the list the same way. It's curated specifically because exploitation is confirmed, not theoretical.

Watch how fast the Langflow exposure count on Shodan drops over the next two weeks. That's the real scoreboard.

© 2026 Threat Vectr