Back Cryptorank Langflow's 12th Exploited CVE of 2026 Fuels Sustained Credential Harvesting Campaign
VulnCheck telemetry shows a rapid spike in Langflow exploitation with over 50 Canary detections on August 30, 2026 and 360+ cumulative by September 1, 2026 centered on CVE-2026-0768 (CVSS 9.8); 12 Langflow CVEs were exploited in 2026 and researchers recorded over 15,000 successful exploitation attempts across related CVEs, with the project having ~153,000 GitHub stars and 399+ contributors. Attackers are conducting credential harvesting of LANGFLOW_SUPERUSER, OpenAI API keys, AWS keys and secret_key files and deploying XMR cryptominers while disabling auditd, with vulnerable hosts concentrated in the US, Germany, Malaysia, Brazil and India, creating material security risk for crypto infrastructure, DeFi/CEX custody and broader adoption.
See what traders are focused on
Telemetry from VulnCheck confirms a sharp escalation in the exploitation of Langflow, an AI framework acquired by IBM through DataStax in 2024. On August 30, 2026, the firm recorded over 50 Canary detections within hours. By September 1, 2026, that figure climbed to more than 360 cumulative detections. This activity centers on CVE-2026-0768, a CVSS 9.8 unauthenticated remote code execution (RCE) flaw in the platform’s code validator, initially disclosed as a zero-day by the Zero Day Initiative (ZDI) on January 9, 2026.
The persistence of this vulnerability is not an isolated event. Throughout 2026, 12 distinct Langflow CVEs have been exploited in the wild, including 11 new vulnerabilities and one identified prior to the start of the year. Across CVE-2026-0769 , CVE-2025-3248 , and CVE-2026-5027 , researchers have documented over 15,000 successful exploitation attempts. The framework, which maintains an ecosystem of over 153,000 GitHub stars, remains a primary target for automated campaigns.
Geographic analysis of internet-exposed hosts shows a significant concentration of vulnerable infrastructure within the United States. Other high-density regions include Germany, Malaysia, Brazil, and India. Attackers are leveraging this global footprint to execute two primary operational profiles: credential harvesting and cryptomining. In the former, adversaries target sensitive environment variables, including LANGFLOW_SUPERUSER, OpenAI API keys, and AWS access and secret keys. They also perform SSH probing and attempt to extract the Langflow secret_key from /root/.cache/langflow/secret_key, while simultaneously auditing .bash_history for further intelligence.
The cryptomining profile involves the deployment of XMR miners, the disabling of auditd to evade detection, and subsequent lateral movement within compromised networks. Caitlin Condon, vice president of threat research at VulnCheck, noted that “adversaries appear to be conducting a mix of reconnaissance and credential harvesting activities.” This assessment aligns with observations of attackers systematically querying system configurations to maximize the utility of their access. As previously detailed in our coverage of Langflow credential harvesting infrastructure , the persistence of these campaigns suggests a highly automated and opportunistic approach.
The exploitation of Langflow highlights a recurring pattern. AI frameworks are deployed with the implicit assumption that the software is hardened by default. When these assumptions fail, the frameworks are repurposed as credential-harvesting infrastructure. The reliance on these tools by developers and enterprises, combined with the rapid pace of vulnerability discovery, creates a persistent security gap. The 399+ contributors to the Langflow project face a continuous cycle of patching that has yet to outpace the speed of attacker adaptation.
The current threat landscape for Langflow is part of a wider trend of AI-centric infrastructure vulnerabilities. analysis has tracked similar patterns in the DIVD Zammad breach , the Bitget $387.5M theft , and the exploitation of FortiMail CVE-2026-104286 . The emergence of the Citrix NetScaler Platypus C2 infrastructure and the rate of AI vulnerability discovery reported by GTIG underscore the risks inherent in modern AI deployment pipelines.
See what traders are focused on
See what traders are focused on
FortiMail’s Encryption Feature Was Supposed to Protect Email. It Became the Attack Vector.
During the September 30 Senate Hearing, Congress Finally Confronted the Rogue AI Agent Problem
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
