Hackers Start Exploiting Critical Langflow Vulnerability
A critical remote code execution vulnerability (CVE-2026-0768) in the Langflow low-code platform is being actively exploited by threat actors, primarily originating from Russia. Attackers are leveraging this flaw to gather sensitive information like environment variables and SSH keys, demonstrating a significant increase in Langflow targeting and exploitation in 2026.
A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-0768, has been identified within the Langflow low-code platform. The vulnerability resides in the code validator component of Langflow’s custom component editor. Because a user-supplied string is not properly validated before being used for Python code execution, attackers can execute arbitrary code as root without requiring authentication. The vulnerability was initially reported to ZDI in July 2025 and publicly disclosed as a zero-day in January 2026. All Langflow releases up to version 1.4.2 are affected. Threat actors have begun exploiting this vulnerability for reconnaissance and credential harvesting operations, with VulnCheck observing a surge in exploitation attempts, particularly from Russia. As of Monday, the cybersecurity firm reported over 360 exploitation attempts hitting its canaries in the UK. Notably, VulnCheck has observed more than 15,000 successful exploitation attempts across three additional known exploited flaws – CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027 – further highlighting the escalating attacker interest in Langflow. This represents a significant shift from previous vulnerability activity, where only one Langflow vulnerability was previously known to be exploited in the wild.