CISA added one new vulnerability to its Known Exploited Vulnerabilities Catalog on March 25, 2026:
CVE-2026-33017 — Langflow Improper Control of Dynamically-Managed Code Resources Vulnerability. Allows unauthenticated remote code execution via the build_public_tmp endpoint.
Federal Civilian Executive Branch agencies are required to remediate this vulnerability by April 8, 2026 per Binding Operational Directive 22-01.
This catalog is a living list of known exploited vulnerabilities that carry significant risk to the federal enterprise.