IBM Langflow RCE Actively Exploited, WordPress Plugin Flaw Revealed
IBM Langflow RCE Flaw Actively Exploited; Critical WordPress Forminator Plugin Vulnerability Disclosed

IBM's Langflow AI platform is under active exploitation, with a critical vulnerability (CVE-2026-9198) allowing unauthenticated remote code execution. Attackers can chain an authentication bypass with code execution to mint superuser tokens and run arbitrary commands. This flaw affects versions 1.0.0 through 1.10.0 and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating immediate risk to organizations using the platform. The vulnerability was detailed in reports from The Register and SecurityWeek, highlighting the urgency for patching.
A critical arbitrary file upload vulnerability in the Forminator Forms WordPress plugin (CVE-2026-15748) affects all versions up to and including 1.56.1, potentially exposing over 600,000 sites. The flaw resides in the handle_file_upload function due to insufficient file type validation, allowing unauthenticated attackers to upload malicious PHP files. This could lead to remote code execution and site compromise. Multiple security outlets, including SecurityWeek and The Hacker News, have reported on this critical issue, emphasizing the widespread risk to WordPress users.
Multiple critical vulnerabilities have been disclosed across various WordPress plugins and themes, including Masteriyo LMS (CVE-2026-73996), Youzify (CVE-2026-73397), Popup by Supsystic (CVE-2026-73380), Ultimate Maps by Supsystic (CVE-2026-73376), Easy Google Maps (CVE-2026-73366), and Sync Post With Other Site (CVE-2026-32463). These flaws primarily involve unauthenticated arbitrary file uploads or PHP object injection, enabling attackers to execute arbitrary code or gain unauthorized access. The widespread nature of these vulnerabilities across popular WordPress extensions underscores the need for diligent plugin management and timely updates.
Critical vulnerabilities have been identified in several other products, including Trendnet TEW-WLC100 (CVE-2026-75784), RegularLabs Sourcerer (CVE-2026-74253), EFM ipTIME A3004T (CVE-2026-19977), MindsDB Minds Platform (CVE-2026-73678), Tenable Security Center (CVE-2026-19682, CVE-2026-19681), Seroval (CVE-2026-59940), ArcadeDB (CVE-2026-75851), Mahara (CVE-2026-42164), PbootCMS (CVE-2026-67960), Systerel S2OPC (CVE-2026-67868), and Q CMS (CVE-2026-67854). These vulnerabilities span a range of impacts, including remote code execution, SQL injection, and improper authentication, affecting diverse sectors from networking equipment to AI platforms and content management systems. The breadth of affected technologies highlights the pervasive nature of security risks across the software landscape.