Search
Find merged stories by title or summary.
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [... ]
Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry. The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations. VulnCheck observed exploitation attempts against its internet-facing Canary systems shortly after the vulnerability was added to its Known Exploited Vulnerabilities catalog. CVE-2026-0768 is an unauthenticated remote code execution flaw in the code validator used by Langflow’s custom component editor. An attacker may be able to execute code on a vulnerable server without first authenticating.
Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Threat actors are actively exploiting two critical remote code execution vulnerabilities affecting Langflow and Ruby on Rails . The campaigns target internet-exposed installations of the low-code AI application platform and the widely deployed web framework, underscoring how rapidly attackers are operationalizing newly disclosed flaws. The first issue, CVE-2026-0768, is an unauthenticated remote code execution vulnerability in Langflow’s custom-component editor. Critical Langflow and Ruby on Rails Flaws The flaw lies in the code-validation path, where insufficient validation of a user-supplied parameter before it is used to execute Python can allow an attacker to run code in the context of the root user. Caitlin Condon said its Canaries began recording first-time exploitation only hours earlier, despite no known public proof-of-concept exploit for the vulnerability.
Hackers Start Exploiting Critical Langflow Vulnerability
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek .
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9. 8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka
You've reached the end of current stories for this search.
