Security Briefing | June 11, 2026 - Langflow RCE Exploited, CISA Issues 3-Day Patch Directive, China Botnet Hits 1,500 Devices
Multiple critical vulnerabilities are under active exploitation, including an unpatched Langflow flaw (CVE-2026-5027) and a max-severity Ivanti Sentry bug. CISA has added three new flaws to its KEV catalog and issued a new directive requiring agencies to patch critical exploited vulnerabilities within three days. China-linked JDY botnet has expanded to over 1,500 devices targeting U.S. military networks, while OceanLotus continues espionage campaigns against Vietnamese entities.
By EACA Summit Content Team

1. Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
A high-severity path traversal vulnerability (CVE-2026-5027, CVSS 8.8) in the open-source AI development platform Langflow is being actively exploited in the wild. The flaw allows unauthenticated attackers to write arbitrary files to the system, leading to remote code execution. Multiple sources confirm exploitation, and no patch is currently available.
Verified Facts
- CVE-2026-5027 is a path traversal vulnerability in Langflow with CVSS score 8.8
- The vulnerability is actively exploited in the wild
- Exploitation allows unauthenticated attackers to write files to arbitrary locations
- No patch is currently available
Evidence
- CVE-2026-5027
- VulnCheck analysis
- Active exploitation reports from The Hacker News, BleepingComputer, and SecurityWeek
Impact
Organizations using Langflow in exposed environments are at immediate risk of full compromise. Defenders should isolate or disable Langflow instances until a patch is released.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
2. CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog; Issues New Patching Directive
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-20245 (Cisco Catalyst SD-WAN Manager), a Chrome vulnerability, and an Arista flaw. Concurrently, CISA issued Binding Operational Directive 26-04, requiring federal agencies to patch critical exploited vulnerabilities within three days.
Verified Facts
- CVE-2026-20245 (CVSS 7.8) is an improper encoding/escaping vulnerability in Cisco Catalyst SD-WAN Manager
- CISA added three vulnerabilities to KEV catalog on June 10, 2026
- CISA issued Binding Operational Directive 26-04 requiring patching of critical exploited flaws within 3 days
- The directive applies to Federal Civilian Executive Branch agencies
Evidence
- CVE-2026-20245
- CISA KEV catalog update
- CISA Binding Operational Directive 26-04
Impact
Defenders should prioritize patching these vulnerabilities within the mandated timeline. The directive signals increased urgency for all organizations to accelerate patch management for actively exploited flaws.
Confidence Level: High
The Hacker News | BleepingComputer
3. China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

The JDY botnet, associated with Chinese state-sponsored threat actors including Volt Typhoon, has expanded to over 1,500 SOHO and IoT devices. The botnet operates as a centrally controlled scanner for discovering and mapping exposed services, with a focus on U.S. military networks.
Verified Facts
- JDY botnet comprises over 1,500 SOHO and IoT devices
- Associated with China-nexus state-sponsored threat actors including Volt Typhoon
- Used for high-performance scanning and reconnaissance of exposed services
- Targeting includes U.S. military networks
Evidence
- Lumen Technologies research
- Reports from The Hacker News and BleepingComputer
Impact
The expansion of JDY indicates increased reconnaissance capabilities against critical infrastructure and military networks. Defenders should monitor for scanning activity from compromised SOHO/IoT devices and review exposure of management interfaces.
Confidence Level: High
The Hacker News | BleepingComputer
Also Noted
OceanLotus (APT32) continues active espionage campaigns targeting Vietnamese government entities and diaspora organizations. Monitoring recommended for organizations with Vietnamese operational ties.
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



