logo

U.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalog

ID: 66a96ce2-1049-506f-8418-f4d515203bbb

STIX ID: report--66a96ce2-1049-506f-8418-f4d515203bbb

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Pierluigi Paganini

...
...

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: a critical Langflow origin validation bug (CVE-2025-34291, CVSS 9.4) that can lead to full system compromise and token exposure and is being abused by the MuddyWater APT, and a Trend Micro Apex One on-premises directory traversal (CVE-2026-34926, CVSS 6.7) that requires prior access but has observed exploitation; federal agencies must remediate by June 4, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.