Frequency
4
occurrences
First Seen
April 4, 2026
Last Seen
August 18, 2026
Related Threat Clusters
-
Critical SQL Injection Vulnerability in Kestra (CVE-2026-34612)
A critical SQL Injection vulnerability, identified as CVE-2026-34612, affects Kestra versions prior to 1.3.7. This vulnerability exists in the GET /api/v1/main/flows/ endpoint of the default Docker Compose deployment,…
2 articles · Updated April 4, 2026 -
Critical Vulnerabilities Discovered in AI Orchestration Platforms
Research presented at DEFCON 34 revealed 14 critical and high severity vulnerabilities across seven AI orchestration platforms, including NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Apache Airflow.…
2 articles · Updated August 18, 2026
Recent Intelligence Reports
- Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design — Reddit · August 18, 2026
- Hacking your life with AI can get you hacked — Endorlabs · August 18, 2026
- CVE-2026-34612 — Mondoo · April 4, 2026
- CVE-2026-34612 - Exploits & Severity — Feedly · April 4, 2026
Related Entities
Data Breach
Remote Code Execution
Sql Injection
Langflow
CVE-2026-34612
CWE-200 - Exposure of Sensitive Information
CWE-287 - Improper Authentication
CWE-78 - OS Command Injection
CWE-94 - Code Injection
T1041 - Exfiltration Over C2 Channel
T1059.004 - Unix Shell
T1059 - Command and Scripting Interpreter