Find notable cyber news and cases, enriched with sources, timelines, and signals.

Langflow unauthenticated RCE flaw (CVE-2026-0770)

Vulnerability
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-0770 in Langflow is an actively exploited vulnerability that lets unauthenticated attackers gain remote code execution as root. CISA ordered U.S. agencies to prioritize patching it, and exploitation had already been seen in the wild before the KEV listing. The flaw creates immediate risk for exposed Langflow deployments because attack activity includes credential harvesting and malware delivery attempts.

Related Happenings

CISA orders FCEB patching under BOD 26-04

Public Sector Action
H score36 First: 22.07.2026 14:43 Last: 22.07.2026 14:43 Sources 1

How related: On Tuesday, CISA added CVE-2026-0770 to its KEV catalog, ordering U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as mandated by Binding Operational Directive (BOD) 26-04.

About this happening: CISA ordered U.S. Federal Civilian Executive Branch agencies to secure systems against CVE-2026-0770 in Langflow, setting a Friday deadline under BOD 26-04...

Adobe ColdFusion path traversal flaw targeted within hours (CVE-2026-48282)

Vulnerability
H score49 First: 07.07.2026 11:20 Last: 07.07.2026 11:20 Sources 1

About this happening: CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution. The latest reporting says exploitation was observed...

MuddyWater broad exploitation wave across exposed SmarterMail, n8n, N-central, Langflow, and Laravel Livewire systems

Exploitation Wave
H score76 First: 06.07.2026 21:34 Last: 06.07.2026 21:34 Sources 1

About this happening: MuddyWater ran a broad exploitation wave across more than 12,000 internet-exposed systems, creating a large attack surface for follow-on access, credential theft, and...

Cavern (Cav3rn) modular C2 framework targeting Israeli organizations

Malware Activity
H score60 First: 06.07.2026 21:34 Last: 06.07.2026 21:34 Sources 1

About this happening: A newly documented Cavern (Cav3rn) C2 framework is giving operators a stronger post-exploitation foothold against Israeli organizations. The toolset is tied to an Ir...

Cavern Manticore campaign targeting Israeli government and IT organizations

Campaign
H score70 First: 06.07.2026 19:00 Last: 06.07.2026 19:00 Sources 1

About this happening: The Cavern Manticore campaign is targeting Israeli government and IT organizations since early 2026, increasing the risk of unauthorized access and data theft...

Timeline

  1. 22.07.2026 14:43 1 articles · 1h ago

    KEVIntel sees CVE-2026-0770 exploitation against Langflow

    Exploitation Observed

    KEVIntel first saw CVE-2026-0770 exploited in the wild on June 27, recording more than 220 attempts from 64 unique source IP addresses against Langflow. The observed activity went beyond simple checks and included payloads that tried to deploy malware and collect AWS credentials, environment variables, container metadata, and second-stage scripts.

    Show sources
  2. 22.07.2026 14:43 2 articles · 1h ago

    CISA adds CVE-2026-0770 to the KEV catalog and orders Langflow patching

    Legal Policy Action Update

    On July 22, CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog and ordered U.S. Federal Civilian Executive Branch agencies to secure Langflow systems by Friday under BOD 26-04. CISA warned that the flaw is a frequent attack vector for malicious cyber actors and told stakeholders to evaluate internet exposure and follow the directive's patching guidance.

    Show sources
  3. 22.07.2026 14:43 1 articles · 1h ago

    Trend Micro traces CVE-2026-0770 to the Langflow validate endpoint

    Technical Analysis Update

    Trend Micro said the flaw lies in handling the exec_globals parameter at the validate endpoint, where unauthenticated attackers can execute code as root through a low-complexity attack. Organizations running Langflow were told to inspect historical requests to /api/v1/validate/code, review host activity, restrict validation access, and rotate exposed credentials if successful execution cannot be ruled out.

    Show sources