Our takeCVE-2026-0768 in Langflow is now exploited in the wild and lets unauthenticated attackers run arbitrary Python code. Patch immediately if you run it yourself.Cyber Resilience desk
Sources (2)
- securityweek · securityweek
- the420_in · the420_in
What this means for you — Security leader:Patch Langflow instances (CVE-2026-0768) immediately if you self-host; the critical unauthenticated RCE is already under active exploitation.
What this means for you — Lean IT orgs:If your team runs Langflow, update it right away — attackers are already using this critical remote code execution flaw.
What this means for you — MSP:Check client environments for self-hosted Langflow and apply the patch for CVE-2026-0768 now; it is under active exploitation.
What this means for you — Researcher:CVE-2026-0768 is a critical unauthenticated RCE in Langflow now being exploited in the wild.