CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

KEV catalog update includes Langflow RCE and Trend Micro Apex One directory traversal flaws under active exploitation

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-34291 in Langflow and CVE-2026-34926 in Trend Micro Apex One, citing active exploitation. CVE-2025-34291, with a CVSS score of 9.4, is an origin validation error enabling arbitrary code execution and full system compromise, exposing sensitive tokens and triggering cascading compromises across integrated services. CVE-2026-34926, rated 6.7, is a directory traversal flaw in on-premise Apex One versions allowing pre-authenticated local attackers with administrative server access to inject malicious code deployable to agents. MuddyWater, an Iranian threat actor, has exploited CVE-2025-34291 for initial access, while Trend Micro observed exploitation attempts for CVE-2026-34926 in the wild. FCEB agencies must remediate by June 4, 2026.

Timeline

  1. 22.05.2026 08:47 1 articles · 12h ago

    CISA KEV update includes Langflow RCE and Trend Micro Apex One directory traversal flaws under active exploitation

    CISA added CVE-2025-34291 (Langflow origin validation error, CVSS 9.4) and CVE-2026-34926 (Trend Micro Apex One directory traversal, CVSS 6.7) to the KEV catalog due to active exploitation. CVE-2025-34291 allows arbitrary code execution and full system compromise via three weaknesses: overly permissive CORS, lack of CSRF protection, and a code-execution endpoint, exposing sensitive tokens and enabling cascading compromises. CVE-2026-34926 permits pre-authenticated local attackers with administrative server access to inject malicious code deployable to agents in on-premise Apex One installations. MuddyWater exploited CVE-2025-34291 for initial access, while Trend Micro observed exploitation attempts for CVE-2026-34926 in the wild. FCEB agencies must remediate by June 4, 2026.

    Show sources

Information Snippets