CISA added Langflow vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of active attacks, ordering U.S. federal agencies to remediate CVE-2026-55255 by July 10. The flaw is an insecure direct object reference in /api/v1/responses that lets an authenticated attacker use a victim flow UUID to access another user's flow, exposing sensitive data and consuming the victim's resources. Reporting also tied Langflow to broader KEV updates, including CVE-2025-3248, a missing-authentication flaw in /api/v1/validate/code that allows unauthenticated remote code execution and was updated in CISA's catalog to show known ransomware use.
Sysdig said it observed in-the-wild exploitation of CVE-2026-55255 on June 25, alongside repeated abuse of CVE-2026-33017, an unauthenticated Langflow RCE that attackers appeared to prefer because it is easier to operationalize and provides direct host compromise. The observed operator enumerated flows through /api/v1/flows/, then abused POST /api/v1/responses with prompts such as "leak api keys" to trigger another tenant's flow and attempt credential theft, while also deploying a malicious Langflow component that fetched a second-stage shell script from 45.207.216.55:8084. Researchers assessed the activity as automated, opportunistic, and financially motivated, combining credential theft, compute abuse, implant delivery, and botnet-style monetization.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After adding the vulnerabilities to KEV, CISA directed federal civilian executive branch agencies to remediate them by 2026-07-10. BleepingComputer also reported that agencies were ordered to prioritize patching the actively exploited Langflow flaw by Friday.
Langflow addressed CVE-2026-55255 in Langflow 1.9.2 and langflow-base 0.4.0. The fix remediates the IDOR issue in the /api/v1/responses endpoint that allowed cross-tenant flow execution and credential theft.
CISA added CVE-2026-55255, CVE-2026-48282, CVE-2026-48908, and CVE-2026-56290 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The newly listed issues affect Langflow, Adobe ColdFusion, JoomShaper SP Page Builder, and Joomlack Page Builder.
On 2026-07-07, CISA's Known Exploited Vulnerabilities catalog was updated so that Langflow CVE-2025-3248 changed from unknown to known ransomware campaign use. The flaw is a missing authentication issue in the /api/v1/validate/code endpoint that can allow remote unauthenticated code execution.
During the observed activity, the same operator enumerated flow UUIDs via /api/v1/flows/ and abused POST /api/v1/responses with the prompt "leak api keys" to execute another tenant's flow via CVE-2026-55255. In parallel, the operator repeatedly exploited Langflow CVE-2026-33017 to inject a malicious component that fetched a second-stage shell script from 45.207.216.55:8084.
On 2026-06-25, Sysdig Threat Research Team documented the first known exploitation of Langflow CVE-2026-55255 in the wild. The activity targeted an exposed Langflow instance and was assessed as opportunistic and financially motivated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcescworld.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcegithub.com
Open sourcecisa.gov
Open sourceadvisories.gitlab.com
Open sourcesysdig.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.