#langflow


Critical Langflow flaw exploited to steal OpenAI and AWS keys

Sep 1, 2026 // 23:37

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and […]

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Sep 1, 2026 // 11:13

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed […]

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

Aug 5, 2026 // 19:17

The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively […]

CISA orders urgent action on actively exploited Langflow RCE flaw

Jul 22, 2026 // 14:56

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for […]

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Jul 21, 2026 // 12:29

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The […]

CISA orders feds to prioritize patching Langflow auth bypass flaw

Jul 8, 2026 // 13:37

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for […]

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

Jul 8, 2026 // 08:39

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active […]

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Jul 2, 2026 // 15:26

Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research […]

Path traversal flaw in AI dev platform Langflow exploited in attacks

Jun 11, 2026 // 00:36

Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. Langflow is […]

Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

Jun 10, 2026 // 18:06

A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, […]

1 2 Next