CISA adds Langflow and Trend Micro vulnerabilities to KEV catalog

Two actively exploited vulnerabilities affecting Langflow and Trend Micro Apex One added to mandatory remediation list for federal agencies.

Illustration: CISA adds Langflow and Trend Micro vulnerabilities to KEV catalog

Two actively exploited vulnerabilities affecting Langflow and Trend Micro Apex One added to mandatory remediation list for federal agencies.

  • CISA added CVE-2025-34291 (Langflow origin validation error) and CVE-2026-34926 (Trend Micro directory traversal) to KEV catalog
  • Both vulnerabilities show evidence of active exploitation in the wild
  • Federal agencies must remediate by specified deadlines under BOD 22-01 requirements

The US Cybersecurity and Infrastructure Security Agency has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation by threat actors.

The additions include CVE-2025-34291, an origin validation error in Langflow, and CVE-2026-34926, a directory traversal vulnerability in Trend Micro Apex One (On-Premise).

CISA established the KEV catalog under Binding Operational Directive 22-01 as a mandatory remediation list for Federal Civilian Executive Branch agencies. The directive requires these agencies to patch listed vulnerabilities by specified due dates to protect federal networks against active threats.

The agency describes these vulnerability types as frequent attack vectors used by malicious cyber actors that pose significant risks to the federal enterprise. CISA continues adding vulnerabilities to the catalog based on specified criteria showing evidence of active exploitation.

While BOD 22-01 applies only to federal agencies, CISA strongly encourages all organisations to prioritise timely remediation of KEV catalog vulnerabilities as part of their vulnerability management practices to reduce exposure to cyberattacks.

The Langflow vulnerability represents an origin validation error that could allow attackers to bypass security controls. The Trend Micro issue involves a directory traversal flaw in the company’s endpoint security platform that could enable unauthorised file access.

Both vulnerabilities joining the KEV catalog indicates threat actors are actively exploiting these flaws in real-world attacks, making them priority targets for security teams managing affected systems.

Why It Matters

CISOs should treat KEV catalog additions as high-priority remediation targets regardless of sector. CISA’s evidence-based approach means these vulnerabilities face active exploitation, creating immediate risk to organisations running affected Langflow or Trend Micro systems.

The KEV catalog serves as a threat intelligence feed for vulnerability prioritisation. CISOs can justify accelerated patching cycles and emergency change windows by referencing CISA’s active exploitation evidence when requesting resources from leadership.

What To Do Now

  • Inventory systems running Langflow and Trend Micro Apex One to identify exposure to these vulnerabilities
  • Check vendor advisories for available patches and apply according to your vulnerability management timeline
  • Monitor CISA’s KEV catalog for additional vulnerabilities requiring priority remediation

Sources