MemTensor's Latest Tag Was the Implant. Clean Builds Lasted Minutes.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
CVE-2026-12944 is a 9.6 authenticated scanner miss in Langflow OSS 1.0.0 through 1.10.0. IBM's fix is 1.10.1. Take 1.10.3 for the password-reset row.
IBM assigned CVE-2026-12944 a 9.6 for Langflow OSS 1.0.0 through 1.10.0. An authenticated user could submit a flow component the scanner marked validated while still running network code as root. IBM's fix for that row is 1.10.1. Take 1.10.3 for CVE-2026-17628, the password-reset miss on 1.0.0 through 1.10.2. No confirmed exploitation yet.
US Google Trends on 16 September were still Steinem, football, and ChatGPT. The searchable operator ticket is CVE-2026-12944. SecurityOnline wrote it up this morning. IBM's score is 9.6. The scanner on Langflow OSS told the operator the component was validated.
GitLab's KEV clock ran out yesterday. This is a different product and a different class: an authenticated miss inside an agent builder, not an unauthenticated file read.
Critical Authenticated component submission, scanner false-pass, code as UID 0. Critical because the box holds the keys the flows use, not because IBM has seen it in the wild.
IBM's bulletin, first dated 2 July and assigned CVE-2026-12944 later, is a blocklist gap in the Langflow component scanner. The scanner already refused subprocess. It did not refuse the network standard library. An authenticated user could submit a component that still ran on the server during validation. The process returned a validated flag anyway.
IBM's description is SSRF and more. The CVSS vector is 9.6 with changed scope: confidentiality and integrity high, availability none, privileges low. The process runs as UID 0. IBM lists cloud-metadata credential theft, file read from the container, and a path to services on the same Docker network. Reporter: KIM MINJUN.
We are not reprinting the component that proves it. The operator fact is enough: if an authenticated user can add a component, a green validated badge is not a sandbox.
Affected builds are Langflow OSS 1.0.0 through 1.10.0. IBM's remediation on that bulletin is 1.10.1. Take it, then keep going.
The same week's second IBM row is CVE-2026-17628, CVSS 5.4, published 8 September. Authenticated callers could change their own password without proving the current one, including to a one-character secret. Affected through 1.10.2. IBM's fix is 1.10.3. SecurityOnline is right to treat 1.10.3 as the build that closes both.
IBM sat on the scanner miss since July. The CVE number and the morning write-ups are what people are searching. There is no KEV row and no IBM statement of in-the-wild use for 12944 or 17628.
That is the difference from CVE-2026-0768, the unauthenticated Langflow RCE CSA and VulnCheck watched being used from 29 August to harvest Langflow tokens, OpenAI keys, and AWS keys. Twelfth exploited Langflow CVE of 2026, CSA said. Do not file 12944 under that campaign. Do file both as reasons the same host should already be off 1.10.x minus the last patch.
It is not unauthenticated. Privileges are low, not none. It is not a stated in-the-wild campaign. It is not every visual agent builder. It is not the GitLab commits-API file read and not the Hugging Face eval swarm.
It is also not a reason to keep 1.10.1 and call the month done. 17628 lives on 1.10.2.
If you run self-hosted Langflow, or you own the cloud keys it holds:
The X debate this week is a Spanish DPA filing and a CEO forecast. The Google-searchable ticket is an agent builder whose own scanner lied. Patch the builder. Then assume the keys on that host were in scope.
You need an authenticated Langflow user who can submit or edit a component. Internet exposure still matters because that user is often a shared service account, an SSO session, or an agent identity. If Langflow holds cloud keys, a root process on the box is a credential harvest even on an internal VLAN.
No. CVE-2026-0768 is the unauthenticated RCE ZDI disclosed in January and that VulnCheck and the Cloud Security Alliance watched being used in late August to pull Langflow tokens, OpenAI keys, and AWS keys. CVE-2026-12944 is a later, authenticated scanner miss. IBM has not called it exploited. Patch both.
1.10.1 is the remediation IBM wrote on the 12944 bulletin. CVE-2026-17628, published 8 September, affects 1.0.0 through 1.10.2: the password-reset path did not check the current password. IBM's fix for that row is 1.10.3. One upgrade covers both.
New or edited flow components you did not approve. Unexpected egress from the Langflow process to cloud metadata or to hosts you do not operate. Password changes that did not go through your IdP. Rotate any API keys, IAM roles, and database credentials that lived on that host, the same way you would after any root-equivalent miss.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
On 18 June an OpenAI research agent wrote files on a Medicare statistics portal. The 10 September notice went to a public mailbox. No patient record is known.
Accomplish found two Codex sandbox escapes. Heapjack ran host commands from read-only. Overpatch wrote outside the workspace. OpenAI fixed both in eight days.