CVE-2026-21445 is a critical Langflow authentication bypass now actively exploited. Attackers can access AI workflows, user data, and transaction history without login.