Threat actors are actively exploiting CVE-2026-0768, a critical unauthenticated remote-code-execution flaw in the Langflow AI low-code platform. Rated CVSS 9.8, the vulnerability affects Langflow versions through 1.4.2 and allows arbitrary Python code execution as root through insufficient validation in the custom-component editor’s code validator. VulnCheck recorded more than 360 exploitation attempts against U.K. canaries, largely from Russian-origin infrastructure, seeking environment variables, Langflow secrets, SSH details, and shell-history metadata.
The activity follows broader disclosures affecting Langflow OSS 1.x releases prior to 1.11.2, including critical and high-severity flaws enabling RCE, privilege escalation, arbitrary file reads, and information disclosure. Organizations should upgrade Langflow to the vendor-fixed releases—at least 1.11.2 where applicable—remove public exposure where possible, rotate credentials accessible to Langflow, and investigate for unauthorized environment-variable access, proxy deployment, cryptomining, audit-log changes, and lateral scanning. Public exploit development is also progressing: a proposed Metasploit module targets the separate authenticated RCE CVE-2026-5027.

See which actors are running it and whether you're in range.
16 events from the most recent confirmed update back to the earliest known activity.
Contributor rmhowe425 proposed and updated a Metasploit multi-platform HTTP exploit module, exploit/multi/http/langflow_unauth_rce_cve_2026_0768, for unauthenticated remote code execution through Langflow CVE-2026-0768. The module is configured with LHOST and RHOSTS values.
By Monday, VulnCheck had recorded more than 360 exploitation attempts against its United Kingdom canary systems targeting CVE-2026-0768. Most observed source traffic originated from Russia and sought environment variables, Langflow secret keys, and SSH-related information.
A GitHub contribution proposed the Metasploit module exploit/multi/http/langflow_auth_rce_cve_2026_5027 for authenticated exploitation of Langflow CVE-2026-5027. The displayed module requires an LHOST, RHOST, username, and password.
VulnCheck recorded more than 50 exploit detections within hours involving active exploitation of critical Langflow CVE-2026-0768 and the KindaRails2Shell Rails flaw, CVE-2026-66066. Langflow activity included reconnaissance and attempts to harvest credentials and secrets.
VulnCheck identified more than 7,100 exposed Ruby on Rails instances vulnerable to CVE-2026-66066 as of early August. The flaw can expose arbitrary server files, Rails environment data, and secrets under applicable Active Storage/libvips configurations.
A security patch for the critical unauthenticated Langflow RCE vulnerability CVE-2026-0768 became available. Langflow versions through 1.4.2 remained vulnerable.
CVE-2026-0768 was publicly disclosed as a Langflow zero-day vulnerability. Langflow releases through version 1.4.2 are affected.
The critical Langflow remote-code-execution vulnerability CVE-2026-0768 was reported through the Zero Day Initiative. The flaw affects the custom component editor code validator and can allow unauthenticated Python code execution as root.
A reported campaign combined unauthenticated Langflow RCE CVE-2026-33017 with the insecure direct object reference flaw CVE-2026-55255. The campaign targeted approximately 7,000 servers to obtain OpenAI and Anthropic API keys, AWS, Google Cloud, Azure, and database credentials.
VulnCheck tested Rails 8.1.3.1 and found that its patch blocked the libvips file-read technique but did not neutralize variation-key Marshal deserialization. It reported that an RCE gadget could still execute on a patched server when supplied with a valid signature.
VulnCheck detected active exploitation of Rails CVE-2026-66066 against canaries in Singapore, Israel, and the United Kingdom. Researcher Patrick Garrity reported that the observed activity originated from one French IP address and communicated with command-and-control infrastructure in Israel.
Attackers exploited CVE-2026-0769 to deploy a payload named .sysd and scan for additional targets, activity assessed as likely intended to expand cryptomining operations.
Attackers weaponized CVE-2025-3248 to add a compromised system to an XMR cryptocurrency-mining botnet. They disabled auditd during the incident, creating a forensic blind spot.
Unknown threat actors exploited Langflow CVE-2026-5027 against a VulnCheck canary, deploying a Python credential harvester, proxy agents, and SimpleHelp remote-access software. VulnCheck also reported over 15,000 successful attacks involving CVE-2026-5027, CVE-2026-0769, and CVE-2025-3248.
Eight vulnerabilities, including two critical and four high-severity issues, were identified in Langflow OSS. Reported impact categories include remote code execution, privilege escalation, arbitrary file reading, and information disclosure; Langflow 1.x releases before 1.11.2 are affected.
IBM announced security updates for six Langflow OSS vulnerabilities: CVE-2026-8446, CVE-2026-9077, CVE-2026-17623, CVE-2026-17625, CVE-2026-17626, and CVE-2026-17630. Versions 1.0.0 through 1.10.3 are affected, and version 1.11.0 or later remediates the listed issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
10 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityaffairs.com
Open sourceheise.de
Open sourcegithub.com
Open sourcegithub.com
Open sourceacn.gov.it
Open sourceboho.or.kr
Open sourcelinkedin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.