Langflow
-
CISA adds four actively exploited flaws, including Adobe ColdFusion bug
CISA added four actively exploited flaws to its Known Exploited Vulnerabilities catalog, including a critical Adobe ColdFusion bug, and told federal civilian agencies to patch by July 10, 2026.
-
Sysdig says AI agent ran ransomware attack through patched Langflow flaw
Sysdig says an AI agent carried out a ransomware attack from start to finish after exploiting a patched Langflow flaw, stealing credentials and encrypting a production database. The report says the case shows how exposed software and weak defaults can be chained automatically.
-
Hackers exploit Langflow flaw to push Monero miner in March-April campaign
Hackers exploited a critical Langflow remote code execution flaw over a 19-day period in March and April 2026 to deploy a Monero miner, disable security tools and spread to other hosts, according to a technical analysis from Trend Micro.
-
Unpatched Langflow flaw under active exploitation, researchers say
An unpatched Langflow flaw tracked as CVE-2026-5027 is being actively exploited, researchers say. The bug can allow arbitrary file writes, and about 7,000 instances are exposed online.
-
CISA adds exploited Langflow and Trend Micro flaws to vulnerability catalog
CISA added exploited flaws in Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities catalog on Thursday, citing active attacks. Federal civilian agencies must patch the issues by June 4, 2026.
-
Critical Langflow RCE CVE-2026-33017 Exploited Within 20 Hours of Disclosure
A critical unauthenticated RCE in Langflow, CVE-2026-33017 (CVSS 9.3), was disclosed on March 17, 2026 and exploited within 20 hours. Users should apply patches, rotate secrets and restrict network access to public instances.
-
New Flodrix Botnet Exploits Vulnerabilities in Langflow Framework
A new botnet campaign exploiting vulnerabilities in the Langflow framework has emerged, allowing attackers to deploy the Flodrix malware. Cybersecurity experts emphasize the urgency of addressing this critical security flaw.






