Langflow

7 items · Attacks 7 · all entities

Attackers move to mass exploitation of a critical Langflow flaw, harvesting AI and cloud credentials

VulnCheck reported more than 50 exploitation attempts within hours on Aug 30 against CVE-2026-0768, an input-validation flaw in the Langflow AI workflow builder that allows arbitrary Python execution in the context of the root user, rising to more than 360 by Sep 1. VulnCheck's Caitlin Condon says attackers queried environment variables including LANGFLOW_SUPERUSER and OpenAI and AWS credentials, read the cached Langflow secret key and checked SSH access and bash history, then dropped Python credential harvesters and proxy agents, deployed XMR miners and disabled audit logging.

Reported by pressVulnCheck (via The Hacker News) ↗ ·

VulnCheck logs more than 15,000 successful exploitation attempts against Langflow

VulnCheck reports its canaries recorded over 15,000 successful attempts against Langflow leveraging three CVEs, with one attacker deploying credential harvesters, proxy agents and remote-access software with IRC command and control and cron persistence, and a second deploying cryptocurrency miners, SOCKS5 tunnels and disabled audit logging before pivoting to scan further targets. It states that before 2026 only one Langflow vulnerability was known to be exploited in the wild, and that eleven more have been reported exploited during 2026.

Reported by researchersVulnCheck ↗ ·

Metasploit ships public exploit modules for two AI application platforms

Rapid7's August 28 Metasploit release added 16 modules, two of them targeting AI application software: an unauthenticated remote code execution exploit for Langflow versions 1.10.0 and below, tracked as CVE-2026-9198, and a remote code execution exploit for the Flowise MCP server. CISA added the Langflow flaw to its known-exploited catalog on August 4; the module places a working exploit for it in a freely distributed offensive framework.

On the recordRapid7 ↗ ·

CISA adds an actively exploited critical RCE in the Langflow AI-agent platform to its KEV catalog

CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog on August 4, a CVSS 9.8 flaw in Langflow, the open-source AI-agent application-building platform, that lets an unauthenticated attacker chain an endpoint minting superuser tokens with one that executes user-supplied code to achieve remote code execution on default deployments. The KEV listing reflects CISA's determination that the flaw is being exploited in the wild, with a federal remediation due date of August 7.

On the recordNIST NVD / CISA KEV ↗ ·

Unit 42 reports Chinese-speaking actor running autonomous attacks with DeepSeek and the Hermes Agent framework

Palo Alto Networks Unit 42 documented a Chinese-speaking threat actor using aliases knaithe and KnYuan who wired DeepSeek into the Hermes Agent framework and orchestrated it over Telegram to autonomously enumerate vulnerabilities, source exploits and launch attacks, including FOFA-driven scanning for exposed Langflow and n8n instances. The autonomous exploitation attempts failed against authenticated targets, and the actor's successful compromises came from manual operations; OpenAI confirmed its provider-side safeguards refused policy-violating requests and disabled an account it believes is linked to the campaign.

Reported by researchersPalo Alto Networks Unit 42 ↗ ·

LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks

Sysdig reports the JadePuffer operator deployed ENCFORGE, Go-based ransomware targeting ~180 AI/ML file types (model checkpoints, vector databases, training data) after exploiting CVE-2025-3248 in Langflow. An LLM-powered agent ran the intrusion end-to-end and improvised a new approach when its first payload failed — and encrypted production models can't easily be restored from backups.

Reported by researchersSysdig / Help Net Security ↗ ·

Sysdig documents JADEPUFFER, an LLM-driven agent that autonomously exploited Langflow and extorted a production database

Sysdig Threat Research reported an intrusion in which an LLM-driven agent exploited CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint, then harvested credentials from the Langflow host and MinIO storage, moved laterally to a production database server, compromised an Alibaba Nacos configuration service, and encrypted 1,342 configuration items using MySQL AES before dropping a ransom demand. Sysdig cited self-narrating payloads containing natural-language reasoning and a 31-second self-correction cycle after an initial exploitation step failed.

Reported by researchersSysdig ↗ ·