Skip to content
Attackers Target AI Development Platform Langflow

Attackers Target AI Development Platform Langflow

F5 • October 6, 2026

September 2026 brought renewed exploitation of React Server Components and Microsoft Exchange vulnerabilities, alongside a new target in our honeynet telemetry: the Langflow AI application-building platform. F5 Labs recorded 405 requests targeting CVE-2026-0768, an unauthenticated remote code execution flaw, from 55 distinct source IPs. This is our first observation of an AI/ML development platform RCE appearing in opportunistic, internet-wide scanning.

The captured payloads reveal more than attempts to identify vulnerable systems. Some tested code execution using unique markers and response delays; others attempted to retrieve environment data that could contain cloud credentials, model API keys, and database secrets. This month’s Sensor Intelligence Series (SIS) examines that activity alongside the leading exploited CVEs and broader traffic trends, highlighting what defenders should prioritize as AI development tools become part of the public-facing attack surface.

AI Development Platform Langflow Unauthenticated RCE (CVE-2026-0768)

Honeynet sensors recorded 405 events matching CVE-2026-0768, an unauthenticated remote code execution flaw in the Langflow AI application-building platform. Every request targeted POST /api/v1/validate/code and supplied Python content in the JSON “code” field. The captured requests included exploitation attempts and benign controls used within probing sequences.

The activity came from 55 distinct source IPs. Differences in payload structure and scanning behavior suggest multiple toolkits, although the requests do not establish how many operators were involved.

F5 Advanced Web Application Firewall (WAF) behavioral tagging placed these 405 events across Server Side Code Injection (405), Command Execution (329), and Information Leakage (310). The overlap is expected from the payload content: the subprocess calls trip command-execution rules, and the environment-dumping behavior trips information-leakage rules. These are the same requests matching several rules, not separate attacks.

The first event occurred on September 11, 2026, roughly seven months after the vulnerability was disclosed. Activity then ran in discrete bursts rather than a steady stream:

Sept 13 to 14: first sustained burst (47 then 40 events)

Sept 26: largest single day at 162 events, 40 percent of the month's total

Sept 28 to 30: tapering to single digits and low tens

The on-and-off pattern, with quiet days between spikes, is consistent with operators running periodic scan sweeps rather than continuous exploitation.

Vulnerability Context

CVE-2026-0768 was disclosed through the Zero Day Initiative (ZDI-26-034) and published January 23, 2026. The NVD record classifies it as CWE-94 (Code Injection) and describes unauthenticated remote code execution through the code parameter on Langflow’s validation endpoint. Successful exploitation runs code with the privileges of the Langflow service process.

At the time of writing, NVD does not display a CVSS base score. Regardless of scoring status, unauthenticated code execution warrants urgent remediation. CVE-2026-0768 is not currently on the CISA KEV catalog. The honeynet evidence of active, multi-source exploitation is the stronger urgency signal here.

How the Vulnerability Works

Langflow exposes a validation endpoint, /api/v1/validate/code, that accepts a string of Python in the JSON “code” field and processes it before any authentication check runs. The flaw is that this user-supplied string is evaluated as Python rather than merely parsed. Two language features give an attacker code execution the moment the server processes the input:

Decorator evaluation : In Python, a decorator expression like @exec(...) runs when the function it decorates is defined, not when the function is called. An attacker who writes the following gets their code executed during definition, before _f is ever invoked. @exec("...")\ndef _f(): pass

@exec("...")\ndef _f(): pass

Default-argument evaluation : Default argument values are evaluated at function-definition time. The following payload executes the exec call when the function is defined. def exploit(cd=exec('...')): pass

def exploit(cd=exec('...')): pass

The vulnerable code-validation handler allows unauthenticated requests to execute Python with the privileges of the Langflow service process. Deployments running that process as root face root-level execution. Other deployments remain exposed to application compromise and potential disclosure of secrets accessible to the process.

Observed Exploit Behavior

All 405 events hit POST /api/v1/validate/code. Three payload families appeared: marker-based capability probing, environment harvesting, and a default-argument execution check. Two dominant infrastructure clusters accounted for the main probing and harvesting activity.

Capability probing with unique markers

Requests from 185.177.72.0/24 included a three-request probing sequence. Example from 185.177.72.38:

{"code":"@exec(\"raise Exception('abp_cvq3zzjptdwg')\")\ndef _f(): pass"}

{"code":"@exec(\"__import__('time').sleep(3)\")\ndef _f(): pass"}

This is a validation harness. The first request abuses decorator evaluation to raise an exception carrying a unique marker string (abp_cvq3zzjptdwg, abp_1x9k76sfoh04, and others). The request is designed to confirm execution if the server returns the injected marker in its error response. The second request, {"code":"pass"}, is a benign control to observe normal behavior. The third is a timing-based execution check: time.sleep(3) is intended to introduce a measurable response delay. The unique-per-request markers let the operator correlate responses to targets at scale. Every request in this family carried User-Agent: curl/8.7.1, consistent with scripted tooling.

This subnet also injected spoofed internal-origin headers: X-Forwarded-For: 127.0.0.1, X-Client-IP: 127.0.0.1, True-Client-IP: 127.0.0.1, and X-Azure-ClientIP: 127.0.0.1. These headers are consistent with attempts to bypass access controls that incorrectly trust client-supplied localhost addresses.

Attempted environment and credential harvesting

Requests from the Google Cloud cluster carried an environment-harvesting payload:

{"code":"@exec('raise Exception(__import__(\"subprocess\").check_output(\"env 2>/dev/null || cat /proc/self/environ 2>/dev/null\",shell=True))')\ndef foo():\npass"}

If executed, the payload runs env and falls back to reading /proc/self/environ if that command fails. It then raises an exception containing the output, attempting to return environment data through the server’s error response. The 2>/dev/null redirection and dual-method fallback show the author expected varied target configurations and wanted clean output.

These GCP requests cycled through a large rotation of forged AI-crawler User-Agent strings: ChatGPT-User, ClaudeBot, PerplexityBot, Googlebot, Baiduspider, Qwenbot, DeepSeekBot, MistralAI-User, CCBot, Bytespider, cohere-ai, Google-Extended, and more. A single IP (35.233.194.235) sent dozens of near-identical payloads while rotating through the list. The identical payload across different User-Agent strings is consistent with an attempt to disguise exploit traffic as crawler activity. These strings do not establish the identity of the requester.

Default-argument variant

One request from 142.93.57.244, a DigitalOcean-range host, used the other injection vector:

{"code": "def exploit(cd=exec('raise Exception(__import__(\"subprocess\").check_output(\"id\", shell=True))')): pass"}

Here execution comes through default-argument evaluation rather than a decorator, and it runs id instead of harvesting the environment. This is a lighter execution check using a different injection pattern from the GCP payload.

The 405 events split across two primary infrastructure clusters with clearly different roles.

Google Cloud cluster (34.x and 35.x ranges): the highest-volume individual sources, led by 35.200.23.10 (86 events), 35.229.191.244 (71), and 35.233.194.235 (29). These carry the environment-harvesting payload with rotating AI-crawler User-Agents.

European scanning subnet (185.177.72.0/24): at least 15 distinct hosts, each contributing 3 to 9 events, running the marker-based capability-probing handshake with plain curl and spoofed localhost headers.

Other hosts : 142.93.57.244 (DigitalOcean) with the default-argument variant, plus single-event sources including two from China (61.163.138.201, 125.46.149.49).

Geographic distribution by infrastructure location: US (127 events), Taiwan (89), Japan (86), France (69), Belgium (24), Ukraine (6), China (3), Canada (1). This reflects where scanning infrastructure is hosted, not actor nationality. Differences in payloads and request patterns suggest distinct tooling, but neither those differences nor infrastructure location establishes operator identity.

The highest-volume CVE-2026-0768 source IPs also generated large volumes of unrelated exploitation during the window, led by CVE-2025-29927 (16,982 events, a .js middleware authorization bypass). The overlapping source IPs suggest infrastructure used for multiple exploitation attempts, with Langflow among the targets.

The payloads reveal structured probing and attempted data extraction, including unique markers, timing checks, fallback commands, and forged User-Agent strings. Capability probing warrants investigation even when no follow-on payload is observed.

Table 1: MITRE ATT&CK mapping

Top CVEs for September 2026

Table 2: Top 10 CVEs for September 2026

The Sep 2026 Top 10 saw significant reshuffling, with three entries joining or returning to the list: CVE-2025-55182 at #1, CVE-2025-55184 at #5, and CVE-2026-4020 at #10. Three CVEs dropped out entirely due to no exploitation activity this month: CVE-2018-14028 (previously #2), CVE-2020-15505 (previously #8), and CVE-2016-4800 (previously #10). The Microsoft Exchange cluster climbed aggressively, with CVE-2021-34523, CVE-2022-41082, and CVE-2021-26855 all advancing into the top four, while legacy PHP-based vectors CVE-2017-9841 and CVE-2018-20062 both fell five positions.

Reentering the top 10, CVE-2025-55182 jumps to #1 with 6,772 attacks and a maximum CVSS score of 10.0. This pre-authentication remote code execution flaw in React Server Components allows attackers to execute arbitrary code without any valid credentials, making it exceptionally dangerous for internet-facing applications built on affected frameworks. Its return to the top position reflects renewed activity in our dataset after two months with no recorded events. Organizations running React Server Components should treat remediation as an emergency priority.

Climbing five positions to #2, CVE-2021-34523 recorded 3,772 attacks, an increase of 1,919 over the prior month. This Microsoft Exchange Server privilege escalation vulnerability (CVSS 9.0) forms part of the ProxyShell exploit chain and enables attackers to elevate privileges within the Exchange environment. Its increase alongside other Exchange CVEs shows renewed targeting of unpatched mail infrastructure. Defenders should verify Exchange patch levels and inspect for post-exploitation web shell artifacts.

Entering the top 10 at #5 with 2,951 attacks, CVE-2025-55184 is a pre-authentication denial-of-service vulnerability in React Server Components rated CVSS 7.5. Paired with its sibling CVE-2025-55182, it reflects adversary interest in both disruption and code execution against the same framework. Like its RCE counterpart, it reactivated this month after recording zero activity in Jul and Aug 2026, consistent with renewed scanning or exploitation activity. While lower severity than an RCE, it poses availability risks to production services and should be patched concurrently.

Dropping five positions to #8 after sustained prominence, CVE-2017-9841 fell by 1,768 attacks to 2,433 this month. This PHPUnit eval-stdin remote code execution flaw (CVSS 9.8) lets attackers execute arbitrary PHP code via an exposed test utility often left in production deployments. Its lower ranking coincided with increased Exchange and React activity, but the data does not establish a shift by the same operators. The vulnerability remains a persistent commodity target, so defenders should not deprioritize removal of development dependencies from live environments.

Making its first appearance at #10 with 1,451 attacks, CVE-2026-4020 is a sensitive information exposure vulnerability in the Gravity SMTP WordPress plugin (CVSS 7.5). It allows unauthenticated actors to retrieve protected credentials and configuration data, which can enable follow-on account compromise and lateral movement. Its appearance in the rankings highlights continued targeting of WordPress plugins. WordPress administrators should audit installed plugins and apply updates promptly.

Long Term Targeting Trends

Figure 1: Six-month stacked graph of the top 5 CVEs.

September 2026 shows broad escalation across all five tracked CVEs, with CVE-2025-55182 leading at 6,772 sessions, its highest monthly total in the available dataset and a rebound after two dormant months (0 in both Jul and Aug 2026). The remaining four CVEs also peaked this month: CVE-2021-34523 hit 3,772 (up from 1,853 in Aug), CVE-2022-41082 reached 3,649 (its highest monthly total in the available dataset), CVE-2021-26855 climbed to 3,475, and CVE-2025-55184 surged to 2,951 after being inactive in Jul and Aug. CVE-2022-41082 has recorded activity in every month since June 2025 and accelerating sharply from roughly 600 to 900 monthly sessions in 2025 to consistently over 2,000 throughout 2026. The simultaneous reactivation of CVE-2025-55182 and CVE-2025-55184 after a two-month lull points to renewed tooling or campaign activity rather than steady background scanning. Defenders should prioritize remediation of the Exchange vulnerabilities associated with ProxyLogon, ProxyShell, and ProxyNotShell given the sustained exploitation attempts, and treat the two 2025 CVEs as active, high-tempo threats whose dormancy does not indicate reduced risk.

Attack Types Over Time

Figure 2: Evolution of attack types over 6 months

Predictable Resource Location remained the dominant category in Sep 2026 at 773,960 events, though it fell 18% from 945,081 the prior month, signaling a slowdown in automated content and path discovery. Information Leakage held second place and climbed 15% to 713,319 from 620,931, indicating sustained interest in exposing misconfigured endpoints and sensitive data. The sharpest relative spike came from Vulnerability Scan activity, which nearly doubled to 17,344 from 8,711, a 99% increase indicating more detected vulnerability-scanning activity. Trojan/Backdoor/Spyware rose 36% to 70,334, while XSS grew 50% to 94,563 and Path Traversal climbed 29% to 100,680, pointing to renewed emphasis on web application compromise and persistence. Defenders should prioritize patching and WAF tuning against traversal and injection vectors, tighten controls on information-disclosure endpoints, and investigate the scanning increase and harden exposed services without assuming that follow-on attacks will occur.

Figure 3: Source country geographical distribution

The US remains the dominant source of attack traffic against our honeynet sensors, climbing to 5,047,003 events in Sep 2026 from 4,567,366 the prior month, a 10.5% increase. France held second place but declined slightly to 2,481,326 from 2,570,248, while Germany surged 44.4% to 1,962,640 from 1,359,473, the sharpest rise among established origins. The most notable development is Indonesia, which tripled to 1,227,657 from 403,578, a 204% jump that vaults it into the top tier of attack sources. China was essentially flat at 809,228 versus 816,154. Defenders should investigate changes in source infrastructure and adjust inspection using request behavior and corroborating indicators. Infrastructure location does not establish actor nationality and should not, by itself, determine blocking policy.

Top Target Destinations

Figure 4: Destination target geographical distribution (normalized per sensor)

Canadian deployments stood out for authentication bypass and middleware traversal attempts aimed at modern web frameworks, a profile sharper than most peer nodes. Sensors recorded both modern framework exploitation attempts and classic remote code execution probes, but their co-occurrence does not establish exploit chaining.

Sensors here absorbed a heavy mix of remote code execution attempts targeting logging frameworks alongside persistent web application exploitation against scripting interpreters. The distinctive feature is the cluster of deserialization and insecure object handling probes, indicating actors systematically testing older server-side vulnerabilities for a foothold.

Traffic here was dominated by command injection and remote code execution attempts against interpreted-language stacks. Its profile leaned heavily toward legacy web scripting flaws, reflecting opportunistic scanning of long-lived unpatched services.

Sensors here recorded mail and collaboration server exploitation attempts aimed at achieving remote code execution. This enterprise-focused targeting, combined with command injection probes, shows targeting of enterprise application vulnerabilities within the observed traffic.

UK sensors recorded steady command injection and web scripting exploitation consistent with broad opportunistic scanning. The relatively uniform attack set points to automated campaigns reusing well-documented remote code execution payloads.

September’s findings show attackers adding new targets to automated exploitation campaigns while continuing to pursue established vulnerabilities. React Server Components flaws returned to the top rankings, and Microsoft Exchange exploitation increased sharply. Langflow CVE-2026-0768 marked our first observation of an AI/ML development platform RCE in opportunistic, internet-wide scanning. Its 405 events were comparatively few, but the captured payloads included execution checks and attempts to harvest environment data, making their potential impact more important than their volume.

The Langflow traffic revealed distinct probing and credential-harvesting toolkits, with some sources also running large volumes of unrelated exploits. Forged AI-crawler User-Agents and spoofed localhost headers illustrated attempts to evade filtering or exploit misplaced trust. Across the wider dataset, Information Leakage rose 15% and Vulnerability Scan activity nearly doubled. These increases warrant closer inspection of exposed endpoints, although honeynet requests alone do not establish successful compromise or predict follow-on attacks.

Defenders should prioritize remediation of internet-facing Langflow and React deployments, verify Exchange patch coverage, and restrict access to development endpoints. Where suspicious code-validation requests are found, investigate for execution and potential secret exposure, rotating affected credentials as needed. WAF controls provide additional protection but cannot replace patching and access restrictions. This month’s results underscore the need to prioritize by exposure and payload behavior, not just attack counts, severity scores, or inclusion in vulnerability catalogs

Upgrade to a release that fixes CVE-2026-0768 immediately. Investigate any vulnerable instance that was internet-reachable during September and treat it as potentially compromised.

Remove direct internet exposure. Place instances behind a VPN or an authenticating reverse proxy.

Restrict POST /api/v1/validate/code to authorized users and trusted networks. Application-layer controls, such as F5 Advanced WAF or F5 Distributed Cloud WAF, can enforce endpoint restrictions while patching is completed.

Credential response for potentially compromised instances:

Where code execution is confirmed or cannot reasonably be ruled out, rotate all secrets available to the Langflow process, including cloud credentials, model API keys, and database credentials.

Replace long-lived static keys with short-lived, narrowly scoped credentials wherever supported.

Enable billing and usage anomaly alerts on model API accounts to detect stolen-key abuse.

Inspect requests to POST /api/v1/validate/code for suspicious Python execution patterns in the JSON code field, including exec, subprocess, __import__, and attempts to read /proc/self/environ. Treat these as indicators, not exhaustive detection rules: payloads can be obfuscated.

Where F5 Advanced WAF is deployed, correlate Server Side Code Injection, Command Execution, and Information Leakage events. A single request may trigger multiple categories.

Do not trust User-Agent strings as evidence of legitimate crawler activity. The observed credential-harvesting requests impersonated several AI crawlers.

Strip or overwrite client-supplied forwarding headers at trusted proxies. Investigate external requests claiming localhost addresses, such as X-Forwarded-For: 127.0.0.1.

Consider temporary blocking of observed scanning sources, including 185.177.72.0/24, as a supplementary measure. Source blocking does not protect against rotating infrastructure.

Inventory AI/ML development platforms and include them in established vulnerability management and network segmentation programs.

Run these services with least privilege, avoid root execution, and limit the credentials available to their processes.

Use WAF protection alongside patching and authenticated access, not as a replacement for either.

Authors & Contributors

Adam Metcalfe-Pearce (Author)

Threat Researcher, F5

Exploit Public-Facing Application (T1190)

Command and Scripting Interpreter (T1059)