Langflow code validator RCE flaw (CVE-2026-0768)
Vulnerability
Summary
Hide ▲
Show ▼
Langflow is being hit by active exploitation of CVE-2026-0768, a critical RCE flaw in the code validator of its custom component editor that can let an attacker run code as root without authentication. The vulnerability affects all Langflow releases up to 1.4.2 and is already being used for reconnaissance and credential harvesting. The exploitation activity raises the risk for exposed Langflow deployments that have not been hardened or remediated.
Related Happenings
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
H score47
First: 31.07.2026 18:00
Last: 31.07.2026 18:00
Sources 1
About this happening:
The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
CampaignAbout this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
Langflow unauthenticated RCE flaw (CVE-2026-0770)
Vulnerability
H score49
First: 22.07.2026 14:43
Last: 22.07.2026 14:43
Sources 1
About this happening:
CVE-2026-0770 in Langflow is an actively exploited vulnerability that lets unauthenticated attackers gain remote code execution as root. CISA ordered U.S. agen...
Langflow unauthenticated RCE flaw (CVE-2026-0770)
VulnerabilityAbout this happening: CVE-2026-0770 in Langflow is an actively exploited vulnerability that lets unauthenticated attackers gain remote code execution as root. CISA ordered U.S. agen...
CISA orders FCEB patching under BOD 26-04
Public Sector Action
H score36
First: 22.07.2026 14:43
Last: 22.07.2026 14:43
Sources 1
About this happening:
CISA ordered U.S. Federal Civilian Executive Branch agencies to secure systems against CVE-2026-0770 in Langflow, setting a Friday deadline under BOD 26-04...
CISA orders FCEB patching under BOD 26-04
Public Sector ActionAbout this happening: CISA ordered U.S. Federal Civilian Executive Branch agencies to secure systems against CVE-2026-0770 in Langflow, setting a Friday deadline under BOD 26-04...
45.207.216[.]55 Langflow IDOR-and-RCE campaign
Campaign
H score34
First: 08.07.2026 08:33
Last: 08.07.2026 08:33
Sources 1
About this happening:
A sustained Langflow exploitation campaign used CVE-2026-55255 and CVE-2026-33017 against an internet-exposed instance, combining reconnaissance, flow enumeration,...
45.207.216[.]55 Langflow IDOR-and-RCE campaign
CampaignAbout this happening: A sustained Langflow exploitation campaign used CVE-2026-55255 and CVE-2026-33017 against an internet-exposed instance, combining reconnaissance, flow enumeration,...
Adobe ColdFusion path traversal flaw targeted within hours (CVE-2026-48282)
Vulnerability
H score49
First: 07.07.2026 11:20
Last: 07.07.2026 11:20
Sources 1
About this happening:
CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution. The latest reporting says exploitation was observed...
Adobe ColdFusion path traversal flaw targeted within hours (CVE-2026-48282)
VulnerabilityAbout this happening: CVE-2026-48282 is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution. The latest reporting says exploitation was observed...
Timeline
-
01.09.2026 15:07 2 articles · 0h ago
Threat actors exploit Langflow CVE-2026-0768 for reconnaissance and credential harvesting
Exploitation ObservedThreat actors used CVE-2026-0768 in Langflow to perform reconnaissance and credential harvesting, including queries for environment variables, secret keys, and SSH access. VulnCheck said the activity was mainly originating from Russia and that its UK canaries had already recorded more than 360 exploitation attempts.
Show sources
- Hackers Start Exploiting Critical Langflow Vulnerability — www.securityweek.com — 01.09.2026 15:07
- Hackers Start Exploiting Critical Langflow Vulnerability — www.securityweek.com — 01.09.2026 15:07
-
01.09.2026 15:07 1 articles · 0h ago
VulnCheck warns of critical Langflow RCE exploitation
Initial DisclosureVulnCheck warned that threat actors have started exploiting CVE-2026-0768 in Langflow, a critical 9.8 RCE in the custom component editor's code validator that can let an attacker run arbitrary code as root without authentication. The flaw was reported through ZDI in July 2025, publicly disclosed as a zero-day in January 2026, and affects all Langflow releases up to version 1.4.2.
Show sources
- Hackers Start Exploiting Critical Langflow Vulnerability — www.securityweek.com — 01.09.2026 15:07