CVE-2026-0768 Exploitation Hits Langflow With 360+ Root RCE Attempts
Active exploitation of an unauthenticated root RCE in Langflow has begun, with over 360 attempts logged targeting credentials. The pattern reveals accelerating attacker focus on AI tooling that processes sensitive data flows. Defenders must prioritize inventory and patching to prevent supply-chain pivots into production systems.
VulnCheck telemetry recorded over 360 exploitation attempts against its UK canaries within days of public zero-day disclosure. Queries focused on environment variables, secret keys, and SSH credentials, with source IPs concentrated in Russia. The flaw stems from missing validation on user-supplied strings passed directly to Python execution inside the code validator.
Langflow instances now face the same rapid targeting pattern seen with 11 other CVEs in 2026, where over 15,000 successful exploits have already occurred across CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027. This marks a sharp departure from prior years when only a single Langflow vulnerability saw in-the-wild use. AI low-code platforms handling data pipelines and automation scripts represent high-value targets for credential harvesting that can pivot into financial or critical infrastructure systems.
The technical evidence shows reconnaissance and data exfiltration activity, distinct from official claims of broad state attribution that lack independent packet or payload confirmation. Unpatched deployments remain exposed because the original ZDI report from July 2025 did not trigger immediate vendor action until public disclosure.
Organizations must inventory Langflow deployments immediately and apply mitigations or upgrades. Continued monitoring of canary hits will likely show whether attackers escalate from credential collection to persistent access or lateral movement within the next 14 days.
VulnCheck: Exploitation attempts against CVE-2026-0768 will exceed 1,000 within 14 days of disclosure.
Sources (3)
- [1]Primary Source(https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/)
- [2]Supporting Source(https://vulncheck.com/blog/langflow-exploitation-2026)
- [3]Supporting Source(https://nvd.nist.gov/vuln/detail/CVE-2026-0768)