Critical CVE-2026-0768 Exploited in Langflow Attacks

Critical CVE-2026-0768 Exploited in Langflow Attacks

First seen 2 Sep 2026, 10:43 UTC Securityaffairs.CoHeise.De 75.0

Article Content

Browse articles
ThreatCluster

Hackers are actively exploiting a critical vulnerability in Langflow, tracked as CVE-2026-0768, which allows unauthenticated remote code execution. The flaw affects all versions up to 1.4.2 of the AI-focused low-code platform Langflow, enabling attackers to execute arbitrary Python code with root privileges. Security researchers from VulnCheck reported over 350 attempted attacks, primarily targeting UK-based systems. The vulnerability was disclosed in January 2026, and a patch has been available since then, but many systems remain unpatched. Attackers are stealing admin credentials and conducting reconnaissance on environment variables. The current exploitation is confirmed to be ongoing, with significant activity observed in recent days. Organizations are urged to apply the available fixes immediately to mitigate risks.

Key Points: • CVE-2026-0768 allows unauthenticated remote code execution in Langflow. • Over 350 exploitation attempts have been reported, primarily targeting UK systems. • A patch has been available since January 2026, but many systems remain vulnerable.

Timeline

2026-01-23
CVE-2026-0768 published
Langflow vulnerability disclosed, allowing remote code execution without authentication.
Securityaffairs.Co
2026-09-01
First public PoC released
Proof-of-concept code for CVE-2026-0768 became publicly available, increasing risk of exploitation.
Securityaffairs.Co
2026-09-02
Active exploitation confirmed
VulnCheck reports over 350 attacks targeting vulnerable Langflow instances, with ongoing exploitation observed.
Heise.De