Skip to content
Langflow IDOR Exploit and Critical Vulnerabilities Targeting AI Platforms

Langflow IDOR Exploit and Critical Vulnerabilities Targeting AI Platforms

First seen 25 Jul 2026, 11:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 26, 2026 at 11:04 UTC
  • •CVE-2026-55255 in Langflow exploited since June 25, allowing unauthorized access to user flows.
  • •CISA added Langflow to its KEV list on July 7, emphasizing its critical status.
  • •CVE-2026-15409 allows unauthenticated attackers to exploit SMA1000 devices, confirmed by Rapid7.

A moderate-scored IDOR vulnerability (CVE-2026-55255) in Langflow has been actively exploited since June 25, 2026, allowing attackers to access and execute flows belonging to other users. This exploit leverages a natural-language prompt to extract sensitive credentials, highlighting a significant oversight in patching priorities based on CVSS scores. The vulnerability was added to CISA's KEV on July 7, 2026, marking it as a critical threat. Additionally, CVE-2026-15409, a critical server-side request forgery flaw in the SMA1000 Workplace web portal, was also reported, allowing unauthenticated attackers to send requests to arbitrary destinations. This vulnerability was confirmed by Rapid7 and SonicWall, affecting multiple models of the SMA1000 series. Security professionals are advised to prioritize patching based on exploitation evidence rather than CVSS scores alone.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 60d ago How this analysis works

Timeline

2026-06-25
Langflow exploit observed in the wild
Attackers began exploiting CVE-2026-55255, allowing unauthorized access to user flows via IDOR.
krypteiasec.com
2026-07-07
CVE-2026-55255 added to CISA KEV
CISA included Langflow in its Known Exploited Vulnerabilities catalog, marking it as critical.
krypteiasec.com
2026-07-14
CVE-2026-15409 published
A critical server-side request forgery flaw in SMA1000 was disclosed, allowing remote exploitation.
krypteiasec.com
2026-07-14
CVE-2026-15410 published
A related vulnerability was disclosed, enabling attackers to chain exploits for code execution.
krypteiasec.com
2026-07-16
CVE-2026-39808 added to CISA KEV
CISA added CVE-2026-39808 to its KEV list, indicating active exploitation.
krypteiasec.com

More articles in this cluster (6)

Following this threat?

Track Inc_ransom, Armored Likho and Anubis in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed