CVE Tools

CISA orders urgent action on actively exploited Langflow RCE flaw

BleepingComputerBy Sergiu Gatlan

Reported exploitedLangflow

Our summary

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. government agencies to address a critical vulnerability in Langflow, a visual framework used for building AI agents. The flaw, tracked as CVE-2026-0770, enables unauthenticated attackers to achieve remote code execution with minimal effort. This vulnerability was recently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation under Binding Operational Directive 26-04. Trend Micro researchers identified the issue in how Langflow processes the exec_globals parameter, allowing attackers to run arbitrary code as root. According to KEVIntel, over 220 exploitation attempts have been recorded since mid-June, with malicious payloads observed stealing AWS credentials and deploying malware.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store