ComfyUI — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
April 8, 2026
Last Seen
August 2, 2026

ComfyUI is a technology platform tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

ComfyUI is a technology platform tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed April 8, 2026; most recent activity August 2, 2026.

Related Threat Clusters

  • ComfyUI Servers Compromised for Cryptomining and Botnet Operations

    A significant wave of cyberattacks has targeted ComfyUI servers, converting them into a botnet for cryptomining and proxy operations. Researchers from Censys reported that since March 12, 2026, over 1,000 publicly…

    3 articles · Updated April 8, 2026
  • Critical RCE Vulnerability in ComfyUI v0.23.0 (CVE-2026-68771)

    ComfyUI v0.23.0 has a critical remote code execution vulnerability (CVE-2026-68771) due to unsafe deserialization in the LoadTrainingDataset node. Unauthenticated remote attackers can exploit this flaw by uploading a…

    2 articles · Updated August 2, 2026
  • Rise of AI-Driven Scams Targeting UK SMEs

    UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…

    757 articles · Updated March 12, 2026

Recent Intelligence Reports

  • CVE-2026-68771 — ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization OSV Advisories — GIT / 19h CVE: CVE-2026-68771 ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a mal — osv.dev · August 2, 2026
  • ComfyUI instances hijacked for cryptomining and proxy botnet | brief — Scworld · April 8, 2026
  • ComfyUI servers: Attackers turn instances into a cryptominer proxy botnet — Heise.De · April 8, 2026
  • Risky Bulletin: Cybercrime losses passed $20 billion last year — Risky.Biz · April 8, 2026

Frequently asked questions

What is ComfyUI?

ComfyUI is a technology platform tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

Is ComfyUI still active?

The most recent intelligence report mentioning ComfyUI on ThreatCluster is dated August 2, 2026. Activity was first observed April 8, 2026, giving a tracked span from then to August 2, 2026.

What is ComfyUI associated with?

Across ThreatCluster reporting, ComfyUI most frequently co-occurs with Botnet, Malware, Zero-day Exploit, Torch, Iran, among 12 tracked related entities.

What are the latest developments involving ComfyUI?

The most significant recent cluster is “ComfyUI Servers Compromised for Cryptomining and Botnet Operations” (3 articles · Updated April 8, 2026). ComfyUI appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on ComfyUI?

ComfyUI appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown