The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two new entries to its Known Exploited Vulnerabilities (KEV) catalog, both targeting widely-used developer and security tools:

  • CVE-2026-33017 — A code injection vulnerability in Langflow, the popular open-source framework for building LLM-powered applications
  • CVE-2026-33634 — An embedded malicious code vulnerability in Aqua Security’s Trivy, a container and infrastructure security scanner

Both vulnerabilities are confirmed to be under active exploitation in the wild. Federal agencies are required to patch within the standard KEV remediation timeline, and CISA is urging all organizations using these tools to prioritize updates.

Source: Cybersecurity Review

Why This Matters

This is a supply-chain security nightmare scenario: the tools developers use to build AI applications (Langflow) and secure their infrastructure (Trivy) are themselves compromised. The Trivy vulnerability is particularly alarming — embedded malicious code in a security scanner means the tool designed to find vulnerabilities was itself a vector. Organizations running either tool in CI/CD pipelines should treat this as critical priority and audit recent scan results for integrity.

By Allan

Leave a Reply

Your email address will not be published. Required fields are marked *