Over the last few months, I researched Langflow, n8n, and Activepieces.
The result is 9 zero-days and a BlueHat IL talk π οΈ
π¨ CVE-2026-7524 (Critical - 9.8)
π¨ CVE-2026-48519 (Critical - 9.6)
β οΈ CVE-2026-7528 (High - 7.1)
π CVE-2026-42228 (Moderate - 6.3)
π CVE-2026-48520 (Moderate - 6.1)
π¨ CVE-not-yet-published (Critical - 9.0)
π¨ CVE-not-yet-published (Critical - 10.0)
β οΈ CVE-not-yet-published (High - 8.6)
β οΈ CVE-not-yet-published (High - 8.3)
Thanks to the vendors for the cooperation and fixes.
@Oranav and I will be breaking down some of these on stage at BlueHat IL 2026
Registration closes soon. Write-ups will be published after the con.
Abstract:
https://t.co/dJfkfwSCvs
@BlueHatIL@msftsecresponse