4SI
All evidence
Validated Presence IncidentScore 88 / CRITICAL

Known-exploited Langflow flaw allowed untrusted functionality to execute

OCCURREDJul 21, 2026
DOMAINAgentic Authority
EVIDENCE ASSURANCEA / Direct institutional record
SOURCEU.S. Cybersecurity and Infrastructure Security Agency

01 / EXECUTIVE SUMMARY

What the evidence
establishes.

CISA added CVE-2026-0770 to the Known Exploited Vulnerabilities Catalog. The Langflow flaw includes functionality from an untrusted control sphere and can allow remote attackers to execute arbitrary code.

02 / WHAT HAPPENED

From accepted signal
to real consequence.

CISA added CVE-2026-0770 to the Known Exploited Vulnerabilities Catalog. The Langflow flaw includes functionality from an untrusted control sphere and can allow remote attackers to execute arbitrary code.

03 / CLAIM-TO-CONSEQUENCE CHAIN

Four stages.
One missing boundary.

The chain distinguishes what appeared valid, what was physically true, which authority followed and what consequence the source documents.

01 / DIGITAL CLAIM

What appeared valid.

An AI workflow component was accepted as part of a trusted execution environment.

02 / PHYSICAL REALITY

What was present.

Functionality supplied from an untrusted control sphere could obtain arbitrary code-execution authority.

03 / AUTHORITY & ACTION

What proceeded.

CISA directed agencies to apply vendor mitigations under BOD 26-04 or discontinue use when mitigations are unavailable.

04 / DOCUMENTED IMPACT

What the source records.

CISA classified the vulnerability as known exploited; the catalog does not quantify attributable loss.

MISSING TRUST BOUNDARY / 4SI ANALYSIS

A verifiable principal and origin boundary for every component allowed to execute inside an agentic workflow.

04 / ECONOMIC CONSEQUENCE RANGE

Evidence before
false precision.

ECR separates a documented monetary floor from a modeled social and economic consequence envelope. It is not an accounting loss figure.

MODELED CONSEQUENCE RANGE

$990K–$30.6M

$5.50MCentral modeled position · USD equivalent
DOCUMENTED FLOOR$0
DATA COVERAGE60%
MODEL MODEproxy led
METHODECR 1.0
UNCERTAINTY

The public record establishes the control failure or authority action, not a realized loss total. The range is a deliberately wide scenario envelope.

05 / 4SI ANALYSIS

Source fact and inference
remain separate.

Exploit status, product and required action come from the official CISA KEV record. 4SI supplies the Presence interpretation and score.

CONNECTION TO THE PRESENCE THESIS

Agentic workflow execution becomes unsafe when component origin is accepted without a current accountable principal.

ANALYTICAL LIMITATION

4SI does not claim to have independently verified the underlying event. Scores, boundary analysis and economic ranges interpret published evidence; they are not probabilities, compliance findings, valuations or loss forecasts.

FROM EVIDENCE TO CONTROL

Presence belongs at the
moment of consequence.