Cyber Resilience
← All news
Corroborated

Hackers Start Exploiting Critical Langflow Vulnerability

Our takeCVE-2026-0768 in Langflow is now exploited in the wild and lets unauthenticated attackers run arbitrary Python code. Patch immediately if you run it yourself.
Sources (2)
What this means for you — Security leader:Patch Langflow instances (CVE-2026-0768) immediately if you self-host; the critical unauthenticated RCE is already under active exploitation.
What this means for you — Lean IT orgs:If your team runs Langflow, update it right away — attackers are already using this critical remote code execution flaw.
What this means for you — MSP:Check client environments for self-hosted Langflow and apply the patch for CVE-2026-0768 now; it is under active exploitation.
What this means for you — Researcher:CVE-2026-0768 is a critical unauthenticated RCE in Langflow now being exploited in the wild.