krypteiasec.com Langflow IDOR Exploit and Critical Vulnerabilities Targeting AI Platforms
Article Content
- •CVE-2026-55255 in Langflow exploited since June 25, allowing unauthorized access to user flows.
- •CISA added Langflow to its KEV list on July 7, emphasizing its critical status.
- •CVE-2026-15409 allows unauthenticated attackers to exploit SMA1000 devices, confirmed by Rapid7.
A moderate-scored IDOR vulnerability (CVE-2026-55255) in Langflow has been actively exploited since June 25, 2026, allowing attackers to access and execute flows belonging to other users. This exploit leverages a natural-language prompt to extract sensitive credentials, highlighting a significant oversight in patching priorities based on CVSS scores. The vulnerability was added to CISA's KEV on July 7, 2026, marking it as a critical threat. Additionally, CVE-2026-15409, a critical server-side request forgery flaw in the SMA1000 Workplace web portal, was also reported, allowing unauthenticated attackers to send requests to arbitrary destinations. This vulnerability was confirmed by Rapid7 and SonicWall, affecting multiple models of the SMA1000 series. Security professionals are advised to prioritize patching based on exploitation evidence rather than CVSS scores alone.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Inc_ransom, Armored Likho and Anubis in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
iTorrents.org Compromised to Distribute MovieReaper Malware iTorrents.org has been compromised to spread a new Windows-based malware called MovieReaper, affecting several hundred victims across multiple countries, including Russia, Japan, and Spain. Kaspersky reported that the malware is distributed through disguised torrents of popular films, leading users to download…
Beware Sparrowock Backdoor Bites Commands Catch 76