AgentsLangflow CVE-2026-27966 CVSS 10.0 CSV Agent RCECybersecurity News·high signalXBlueskyLinkedInCopy linkThird CVSS 10.0 agent platform RCE in 6 weeks. Langflow shipped with allow_dangerous_code=True permanently enabled.SourceSource pageCybersecurity News↳ Follow the threadPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Stack layer / Threat patternIBM discloses four critical MCP flaws in Langflow and ContextForge, three of them command execution through MCP stdio configurationNVD / IBM Security BulletinStack layer / Threat patternGoogle's Agent Development Kit for Python Carries a CVSS 10.0 Unauthenticated RCE via Test Session ReplayOffSeq Threat RadarStack layer / Threat patternAWS Security Agent MCP server could hand a scanned workspace's source archive, credentials included, to an attacker-owned S3 bucketNVDStack layer / Threat patternAnthropic's September threat report documents autonomous agent swarms, 13 unsupervised collection agents, and a developer token escalated to full admin in three hoursAnthropicStack layer / Threat patternProduct Hunt's September 9 Board Was Agent Infrastructure Top to Bottom, With Meta's Consumer Muse Only Reaching Number FiveProduct Hunt daily leaderboard (Muse pricing corroborated by The Neuron's September 9 digest)Stack layer / Threat patternSequoia doubled down on Cymphony, which tracks AI agents as identities alongside employeesTechCrunchThreat pattern / Update threadIBM discloses three high-severity Langflow CVEs, including authenticated RCE via path traversal and API keys that outlive user deactivationGitHub Security Advisories