Critical Langflow RCE Flaw Exploited to Harvest Credentials

Critical Langflow RCE Flaw Exploited to Harvest Credentials

First seen 1 Sep 2026, 19:59 UTC CybersecuritynewsBleepingcomputer 77.0

Article Content

Browse articles
ThreatCluster

Threat actors are exploiting a critical unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for AI applications, to steal sensitive credentials, including AWS and OpenAI keys. VulnCheck reported over 360 exploitation attempts, primarily from Russia, targeting environment variables and administrative credentials. The flaw, disclosed in January 2026, allows attackers to execute arbitrary code without authentication. This vulnerability is part of a series of critical issues affecting Langflow, with previous exploits occurring earlier in 2026. Users are urged to upgrade to secure versions immediately. The situation is evolving, with active exploitation confirmed as of today.

Key Points: • CVE-2026-0768 allows unauthenticated remote code execution in Langflow. • Over 360 exploitation attempts have been observed, mainly from Russia. • Users are advised to upgrade Langflow to secure versions immediately.

Timeline

2026-01-23
CVE-2026-0768 published
A critical RCE vulnerability in Langflow was disclosed, affecting versions 1.4.2 and earlier.
Bleepingcomputer
2026-03-20
CVE-2026-33017 published
A critical code-injection flaw in Langflow was disclosed, leading to immediate exploitation.
Bleepingcomputer
2026-03-27
CVE-2026-5027 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-23
CVE-2026-55255 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-17
CVE-2026-9198 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-0770 added to CISA KEV
CISA confirmed active exploitation of another Langflow vulnerability, CVE-2026-0770.
Bleepingcomputer
2026-09-01
Active exploitation of CVE-2026-0768 confirmed
VulnCheck reported over 360 exploitation attempts targeting Langflow's RCE vulnerability.
Bleepingcomputer