Attackers Exploit Critical Langflow RCE CVE-2026-0768 to Harvest AI Cloud Credentials

VulnCheck reports active exploitation of Langflow CVE-2026-0768 (CVSS 9.8), an unauthenticated root RCE in the custom component editor used for recon and harvesting OpenAI, AWS, and Langflow secrets.

Langflow CVE-2026-0768 exploited for AI credential harvesting
Langflow CVE-2026-0768 exploited for AI credential harvesting

Threat actors have begun actively exploiting CVE-2026-0768, a critical remote code execution flaw in the open-source AI low-code platform Langflow, according to SecurityWeek’s coverage of VulnCheck findings and a parallel The Hacker News report. The bug scores CVSS 9.8: Langflow’s custom component editor fails to properly validate a user-supplied string before using it for Python execution, allowing unauthenticated attackers to run arbitrary code as root. SecurityWeek states all Langflow releases up to version 1.4.2 are affected; the issue was reported through Zero Day Initiative in July 2025 and disclosed as a zero-day in January 2026 (ZDI-26-034).

VulnCheck says exploit traffic is aimed at reconnaissance and credential harvesting rather than noise alone. The Hacker News quotes VulnCheck’s Caitlin Condon describing requests that query environment variables including LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS*, and AWS_SECRET*, read /root/.cache/langflow/secret_key, and check .ssh access and .bash_history size. Source traffic primarily originates from Russia and, in VulnCheck’s canary set, has hit UK sensors. SecurityWeek and THN report more than 360 exploitation attempts against those UK canaries by Monday, September 1, 2026 (THN notes detections rose from more than 50 within hours on August 30 to 360 by Monday).

Broader Langflow targeting in 2026

CVE-2026-0768 sits inside a sharper 2026 focus on Langflow as an AI development surface. SecurityWeek cites VulnCheck saying that before 2026 only one Langflow vulnerability was known to be exploited in the wild, while in 2026 the firm has seen 11 additional vulnerabilities targeted and reported as exploited. VulnCheck has observed more than 15,000 successful attacks against instances vulnerable to CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027. THN adds that hosts clustered in the United States, Germany, Malaysia, Brazil, and India, and that related Langflow CVEs have been used to drop credential harvesters, remote-access tooling, and cryptomining payloads in other campaigns.

What defenders should do now

SecurityWeek’s summary of the affected range stops at Langflow 1.4.2; neither SecurityWeek nor the THN Langflow section states a single unambiguous “fixed in X.Y.Z” build in the passages verified for this brief, so operators should treat any install at or below 1.4.2 as vulnerable, upgrade to a current vendor-supported release beyond that floor, and keep Langflow off the public internet unless tightly authenticated and network-restricted. If an instance was exposed, rotate Langflow, OpenAI, AWS, and related secrets and audit SSH and history artifacts the probes target.

Primary sources for this brief are SecurityWeek’s Langflow exploitation article, The Hacker News’ September report on Langflow and Rails credential-probing activity, and the ZDI advisory for CVE-2026-0768.

Topics
  • #Cyber Security
  • #AI Agents
  • #Opensource
Raj M

Author

Raj M

Contributor

AI Systems Architect is a seasoned technology leader with over 15 years of experience in the IT industry working with Fortune 500 companies. With a solid foundation in multi-agent systems, open-source LLM infrastructure, and enterprise deployment, he excels at building scalable production-grade AI platforms.