Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-08-05

HighPrimary

Check Point Black Hat 2026: 12 CVEs Disclosed Across 6 Major AI Agent Frameworks, Langflow CVE-2026-9198 Enters CISA KEV

Deep dive into Check Point's Black Hat 2026 disclosure of 12 CVEs across 6 major agent frameworks (Langflow, Microsoft, Google, AutoGen, CrewAI).

Langflow / FrameworksGovernance bypassDeserialization RCE, Unauthenticated API Access, and Sandbox EscapeAI agent execution environments and middleware services

What happened

An attacker injects a malicious payload into a database or message stream; the agent framework parses the object, executing RCE or bypassing sandboxes.

Why it matters

Full compromise of backend agent runtimes, unauthorized cloud deployments, and lateral database access.

Missing authorization check

All framework-level database queries and local code executions must require out-of-band, cryptographically-signed authorization receipts.

Would PP block it?

Even if an attacker exploits a deserialization or unauthenticated API flaw in Langflow or Microsoft Agent Framework to execute arbitrary code within the framework workspace, they cannot authorize sensitive external actions. Any file commit, CRM export, or AWS call is intercepted by PP's gates, requiring an out-of-band human-signed cryptographic receipt that the compromised framework cannot generate.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-04

    CISA adds Langflow CVE-2026-9198 (CVSS 9.8) to the Known Exploited Vulnerabilities (KEV) catalog.

  2. 2026-08-05

    Check Point researchers Tal & Porat present 'No Tools Required' at Black Hat USA, disclosing 12 CVEs across 6 agent frameworks.

Technical breakdown

  • In Microsoft Agent Framework, attackers exploited unsafe python pickle/deserialization on session checkpoints.
  • In Google ADK, the default build-helper server launched unauthenticated HTTP endpoints on cloud run, permitting unauthenticated RCE.
  • In Cloudflare workerd, prompt injection was chained with memory-corruption to execute a full sandbox breakout.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Tool-Call Gate, Deploy Gate
Still needs
PP does not block local code execution occurring entirely inside the framework's compromised serialization workspace.
Receipt required for
Initiating cloud deployments, executing database modifications, or launching external shell scripts

Framework internals can be compromised, but PP's external signing keys remain secure and isolated.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop