Metasploit updates two Langflow RCE modules
Rapid7 updated Metasploit modules for Langflow RCE flaws CVE-2026-7873 and CVE-2026-0769, with no in-the-wild claims.
Two Rapid7 Metasploit Framework commits on 2026-10-08 update existing Langflow remote-code-execution modules rather than report new attacks. One commit revises modules/exploits/multi/http/langflow_auth_rce_cve_2026_7873.rb, whose name indicates authenticated HTTP RCE for CVE-2026-7873. A later commit the same day revises modules/exploits/multi/http/langflow_unauth_rce_cve_2026_0769.rb for unauthenticated HTTP RCE tracked as CVE-2026-0769. Both changes are co-authored by Brendan. The commit messages do not give affected versions, patches, victims, or confirmation of exploitation in the wild. The sources cover different CVEs and do not contradict each other.
- On 2026-10-08, Rapid7 Metasploit Framework commits updated two Langflow HTTP exploit modules.
- modules/exploits/multi/http/langflow_auth_rce_cve_2026_7873.rb targets authenticated remote code execution tracked as CVE-2026-7873.
- modules/exploits/multi/http/langflow_unauth_rce_cve_2026_0769.rb targets unauthenticated remote code execution tracked as CVE-2026-0769.
- Both commits were co-authored by Brendan and record module updates only.
- Neither commit describes affected versions, a fix, victims, or confirmed in-the-wild exploitation.
Coverage timelineoldest first · each row is one article
- · 8h agoUpdate modules/exploits/multi/http/langflow_auth_rce_cve_2026_7873.rb
Metasploit Framework commits· 48
Metasploit updated its authenticated RCE module for Langflow flaw CVE-2026-7873.
- · 5h agoUpdate modules/exploits/multi/http/langflow_unauth_rce_cve_2026_0769.rb
Metasploit Framework commits· 48
Metasploit updated its Langflow unauthenticated RCE module for CVE-2026-0769.