news.mlab.sh
1 result
vulnerability

Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

A critical vulnerability, CVE-2026-5027, in the Langflow low-code platform has been actively exploited, allowing for remote code execution due to a lack of input sanitization. This flaw, combined with unauthenticated auto-login, has enabled attackers to write files to arbitrary locations on victim systems. The exploita…

The Hacker News · Jun 10, 2026 Critical