Everything tagged vulnerability.
An unsanitized file-upload endpoint allows remote code execution, and Langflow's default unauthenticated auto-login makes exploitation trivial.
CVE-2026-10520 is a CVSS 10.0 unauthenticated bug that hands attackers root. Researchers found at least two exposed instances already backdoored.
The update is the largest on record and includes three publicly disclosed zero-days in BitLocker, HTTP.sys and Windows CTF.