Skip to content
Exploitation of Langflow Flaws via Commodity Crawlers

Exploitation of Langflow Flaws via Commodity Crawlers

First seen 16 Sep 2026, 21:20 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 22:55 UTC
  • Two CVEs (CVE-2025-3248, CVE-2026-0770) exploited in Langflow with thousands of attempts.
  • 95% of attacks traced to two hosting providers, indicating concentrated malicious activity.
  • Significant SSH and Remote Desktop crawling observed, emphasizing the need for immediate patching.

Adversaries have exploited two known remote code execution vulnerabilities in the AI application platform Langflow, specifically CVE-2025-3248 and CVE-2026-0770. These exploits were detected during a period of active commodity crawling, with 3,968 and 4,770 connection attempts recorded respectively. Approximately 95% of the malicious activity originated from two hosting providers, indicating a concentrated source of attacks. The attackers also engaged in SSH enumeration and credential attacks, with four hosts accounting for 36% of alternative-port SSH crawling. Additionally, one address was responsible for over half of the Remote Desktop crawling observed. GreyNoise has advised users to patch Langflow and monitor the identified sources for malicious activity. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog, highlighting their active exploitation status.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-04-07
CVE-2025-3248 published
Remote code execution flaw in Langflow disclosed, affecting multiple versions.
www.greynoise.io
2025-05-05
CVE-2025-3248 added to CISA KEV
CISA confirmed active exploitation of CVE-2025-3248, alerting organizations to the risk.
www.greynoise.io
2026-01-23
CVE-2026-0770 published
Another remote code execution vulnerability in Langflow disclosed, affecting the platform.
www.greynoise.io
2026-07-21
CVE-2026-0770 added to CISA KEV
CISA confirmed active exploitation of CVE-2026-0770, advising immediate action.
www.greynoise.io
2026-09-14
Active exploitation detected
Adversaries attempted CVE-2025-3248 and CVE-2026-0770 during a commodity crawling sweep.
www.greynoise.io

More articles in this cluster (2)

Following this threat?

Track Langflow and CVE-2025-3248 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed