Langflow IDOR Exploit and Critical Vulnerabilities Targeting AI Platforms

Langflow IDOR Exploit and Critical Vulnerabilities Targeting AI Platforms

First seen 25 Jul 2026, 11:25 UTC Buttondownkrypteiasec.com 93% similarity 72.0

Article Content

Browse articles
ThreatCluster

A moderate-scored IDOR vulnerability (CVE-2026-55255) in Langflow has been actively exploited since June 25, 2026, allowing attackers to access and execute flows belonging to other users. This exploit leverages a natural-language prompt to extract sensitive credentials, highlighting a significant oversight in patching priorities based on CVSS scores. The vulnerability was added to CISA's KEV on July 7, 2026, marking it as a critical threat. Additionally, CVE-2026-15409, a critical server-side request forgery flaw in the SMA1000 Workplace web portal, was also reported, allowing unauthenticated attackers to send requests to arbitrary destinations. This vulnerability was confirmed by Rapid7 and SonicWall, affecting multiple models of the SMA1000 series. Security professionals are advised to prioritize patching based on exploitation evidence rather than CVSS scores alone.

Key Points: • CVE-2026-55255 in Langflow exploited since June 25, allowing unauthorized access to user flows. • CISA added Langflow to its KEV list on July 7, emphasizing its critical status. • CVE-2026-15409 allows unauthenticated attackers to exploit SMA1000 devices, confirmed by Rapid7.

ThreatCluster AI

Timeline

2026-06-25
Langflow exploit observed in the wild
Attackers began exploiting CVE-2026-55255, allowing unauthorized access to user flows via IDOR.
krypteiasec.com
2026-07-07
CVE-2026-55255 added to CISA KEV
CISA included Langflow in its Known Exploited Vulnerabilities catalog, marking it as critical.
krypteiasec.com
2026-07-14
CVE-2026-15409 published
A critical server-side request forgery flaw in SMA1000 was disclosed, allowing remote exploitation.
krypteiasec.com
2026-07-14
CVE-2026-15410 published
A related vulnerability was disclosed, enabling attackers to chain exploits for code execution.
krypteiasec.com
2026-07-16
CVE-2026-39808 added to CISA KEV
CISA added CVE-2026-39808 to its KEV list, indicating active exploitation.
krypteiasec.com

Community

Browse all →