Langflow unauthenticated RCE flaw (CVE-2026-0770)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-0770 in Langflow is an actively exploited vulnerability that lets unauthenticated attackers gain remote code execution as root. CISA ordered U.S. agencies to prioritize patching it, and exploitation had already been seen in the wild before the KEV listing. The flaw creates immediate risk for exposed Langflow deployments because attack activity includes credential harvesting and malware delivery attempts.
Related Happenings
CISA orders FCEB patching under BOD 26-04
Public Sector Action
H score36
First: 22.07.2026 14:43
Last: 22.07.2026 14:43
Sources 1
How related:
On Tuesday, CISA added CVE-2026-0770 to its KEV catalog, ordering U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as mandated by Binding Operational Directive (BOD) 26-04.
About this happening:
CISA ordered U.S. Federal Civilian Executive Branch agencies to secure systems against CVE-2026-0770 in Langflow, setting a Friday deadline under BOD 26-04...
CISA orders FCEB patching under BOD 26-04
Public Sector ActionHow related: On Tuesday, CISA added CVE-2026-0770 to its KEV catalog, ordering U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as mandated by Binding Operational Directive (BOD) 26-04.
About this happening: CISA ordered U.S. Federal Civilian Executive Branch agencies to secure systems against CVE-2026-0770 in Langflow, setting a Friday deadline under BOD 26-04...
Adobe ColdFusion path traversal flaw targeted within hours (CVE-2026-48282)
Vulnerability
H score49
First: 07.07.2026 11:20
Last: 07.07.2026 11:20
Sources 1
About this happening:
CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution. The latest reporting says exploitation was observed...
Adobe ColdFusion path traversal flaw targeted within hours (CVE-2026-48282)
VulnerabilityAbout this happening: CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution. The latest reporting says exploitation was observed...
MuddyWater broad exploitation wave across exposed SmarterMail, n8n, N-central, Langflow, and Laravel Livewire systems
Exploitation Wave
H score76
First: 06.07.2026 21:34
Last: 06.07.2026 21:34
Sources 1
About this happening:
MuddyWater ran a broad exploitation wave across more than 12,000 internet-exposed systems, creating a large attack surface for follow-on access, credential theft, and...
MuddyWater broad exploitation wave across exposed SmarterMail, n8n, N-central, Langflow, and Laravel Livewire systems
Exploitation WaveAbout this happening: MuddyWater ran a broad exploitation wave across more than 12,000 internet-exposed systems, creating a large attack surface for follow-on access, credential theft, and...
Cavern (Cav3rn) modular C2 framework targeting Israeli organizations
Malware Activity
H score60
First: 06.07.2026 21:34
Last: 06.07.2026 21:34
Sources 1
About this happening:
A newly documented Cavern (Cav3rn) C2 framework is giving operators a stronger post-exploitation foothold against Israeli organizations. The toolset is tied to an Ir...
Cavern (Cav3rn) modular C2 framework targeting Israeli organizations
Malware ActivityAbout this happening: A newly documented Cavern (Cav3rn) C2 framework is giving operators a stronger post-exploitation foothold against Israeli organizations. The toolset is tied to an Ir...
Cavern Manticore campaign targeting Israeli government and IT organizations
Campaign
H score70
First: 06.07.2026 19:00
Last: 06.07.2026 19:00
Sources 1
About this happening:
The Cavern Manticore campaign is targeting Israeli government and IT organizations since early 2026, increasing the risk of unauthorized access and data theft...
Cavern Manticore campaign targeting Israeli government and IT organizations
CampaignAbout this happening: The Cavern Manticore campaign is targeting Israeli government and IT organizations since early 2026, increasing the risk of unauthorized access and data theft...
Timeline
-
22.07.2026 14:43 1 articles · 1h ago
KEVIntel sees CVE-2026-0770 exploitation against Langflow
Exploitation ObservedKEVIntel first saw CVE-2026-0770 exploited in the wild on June 27, recording more than 220 attempts from 64 unique source IP addresses against Langflow. The observed activity went beyond simple checks and included payloads that tried to deploy malware and collect AWS credentials, environment variables, container metadata, and second-stage scripts.
Show sources
- CISA orders urgent action on actively exploited Langflow RCE flaw — www.bleepingcomputer.com — 22.07.2026 14:43
-
22.07.2026 14:43 2 articles · 1h ago
CISA adds CVE-2026-0770 to the KEV catalog and orders Langflow patching
Legal Policy Action UpdateOn July 22, CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog and ordered U.S. Federal Civilian Executive Branch agencies to secure Langflow systems by Friday under BOD 26-04. CISA warned that the flaw is a frequent attack vector for malicious cyber actors and told stakeholders to evaluate internet exposure and follow the directive's patching guidance.
Show sources
- CISA orders urgent action on actively exploited Langflow RCE flaw — www.bleepingcomputer.com — 22.07.2026 14:43
- CISA orders urgent action on actively exploited Langflow RCE flaw — www.bleepingcomputer.com — 22.07.2026 14:43
-
22.07.2026 14:43 1 articles · 1h ago
Trend Micro traces CVE-2026-0770 to the Langflow validate endpoint
Technical Analysis UpdateTrend Micro said the flaw lies in handling the exec_globals parameter at the validate endpoint, where unauthenticated attackers can execute code as root through a low-complexity attack. Organizations running Langflow were told to inspect historical requests to /api/v1/validate/code, review host activity, restrict validation access, and rotate exposed credentials if successful execution cannot be ruled out.
Show sources
- CISA orders urgent action on actively exploited Langflow RCE flaw — www.bleepingcomputer.com — 22.07.2026 14:43