The AI app builder your team trusts has a root-level backdoor
Attackers actively exploit unauthenticated RCE CVE-2026-0768 (CVSS 9.8) in internet-facing Langflow instances to run code as root and steal credentials.
VulnCheck observed continuous exploitation of Langflow CVE-2026-0768 (CVSS 9.8) against internet-facing instances starting August 29, 2026; the validate endpoint passes submitted code directly to Python exec() with no input validation and often no authentication, giving unauthenticated root code execution. Attackers harvest .env files, OpenAI API keys, AWS credentials, SSH keys, and source code, then attempt lateral movement; VulnCheck logged 360+ attempts on UK honeypots, mostly from Russia. Over 15,000 successful exploitation attempts were recorded across three related Langflow flaws (CVE-2026-0769, CVE-2025-3248, CVE-2026-5027), and all versions up to and including 1.4.2 are affected. Twelve Langflow vulnerabilities have been exploited in the wild in 2026 alone.