Skip to content
Langflow AI Platform Targeted by RCE Exploitation

Langflow AI Platform Targeted by RCE Exploitation

First seen 7 Oct 2026, 09:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 10:57 UTC
  • •CVE-2026-0768 allows unauthenticated RCE on Langflow, with a CVSS score of 9.8.
  • •Over 405 exploitation attempts were recorded from 55 distinct IPs in September 2026.
  • •Attackers are targeting sensitive data, including cloud credentials and API keys.

In September 2026, the Langflow AI application-building platform faced significant exploitation attempts targeting CVE-2026-0768, an unauthenticated remote code execution vulnerability. F5 Labs reported 405 requests from 55 distinct source IPs, indicating a coordinated effort to exploit this flaw. The vulnerability allows attackers to execute arbitrary Python code via a validation endpoint without authentication. Exploitation attempts began in late August, with a peak of 162 events recorded on September 26. Attackers are reportedly harvesting sensitive data such as cloud credentials and API keys. The vulnerability was disclosed on January 23, 2026, and has a CVSS score of 9.8, marking it as. As of now, exploitation in the wild is confirmed, raising urgent concerns for organizations using Langflow.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2017-04-13
CVE-2016-4800 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-06-27
CVE-2017-9841 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-08-10
CVE-2018-14028 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2018-12-11
CVE-2018-20062 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-07-07
CVE-2020-15505 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-03-02
CVE-2021-26855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-07-14
CVE-2021-34523 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-09-30
CVE-2022-41082 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2025-03-21
CVE-2025-29927 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-04-07
CVE-2025-3248 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (4)

Following this threat?

Track AWS and CVE-2016-4800 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-0768?
CVE-2026-0768 is a critical unauthenticated remote code execution vulnerability in the Langflow platform.
How can I protect my organization?
Organizations using Langflow should immediately assess their exposure and apply any available patches or mitigations.
What data is at risk?
Attackers may exfiltrate sensitive data such as cloud credentials, API keys, and SSH keys from compromised Langflow instances.