Exploitation of Langflow Flaws via Commodity Crawlers
Article Content
- •Two CVEs (CVE-2025-3248, CVE-2026-0770) exploited in Langflow with thousands of attempts.
- •95% of attacks traced to two hosting providers, indicating concentrated malicious activity.
- •Significant SSH and Remote Desktop crawling observed, emphasizing the need for immediate patching.
Adversaries have exploited two known remote code execution vulnerabilities in the AI application platform Langflow, specifically CVE-2025-3248 and CVE-2026-0770. These exploits were detected during a period of active commodity crawling, with 3,968 and 4,770 connection attempts recorded respectively. Approximately 95% of the malicious activity originated from two hosting providers, indicating a concentrated source of attacks. The attackers also engaged in SSH enumeration and credential attacks, with four hosts accounting for 36% of alternative-port SSH crawling. Additionally, one address was responsible for over half of the Remote Desktop crawling observed. GreyNoise has advised users to patch Langflow and monitor the identified sources for malicious activity. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog, highlighting their active exploitation status.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Langflow and CVE-2025-3248 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw affects numerous applications…
Multiple Exploits Targeting Android and Web Applications A cluster of cybersecurity tools has emerged, targeting various vulnerabilities in Android and web applications. The tools include AndroTickler, designed for penetration testing of Android apps, and exposecheck, which checks for authentication vulnerabilities in the Langflow framework related to CVE-2025-3248.…