CVE-2026-0770Active Exploitation(langflow / langflow)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-24. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-829

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 21 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 31 mentions across 16 observed days

What's happening

  • Active exploitation reported across 21 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 27 signals
  • Disclosure: 4 classified signals
  • Peaked 12d ago at 6 mentions (2026-07-21); latest day: 1
  • 31 total mentions across 16 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline31 mentions / 16d
02356Mentions · 2026-02-19: 1Mentions · 2026-02-22: 1Mentions · 2026-06-10: 1Mentions · 2026-07-21: 6Mentions · 2026-07-22: 6Mentions · 2026-07-23: 5Mentions · 2026-07-24: 1Mentions · 2026-07-26: 2Mentions · 2026-07-29: 1Mentions · 2026-07-30: 1Mentions · 2026-08-03: 1Mentions · 2026-08-04: 1Mentions · 2026-08-13: 1Mentions · 2026-08-18: 1Mentions · 2026-09-16: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-07-21: 1PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-08-13: 1Exploit Tool / Code · 2026-02-19: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-07-21: 5Active Exploitation · 2026-07-22: 4Active Exploitation · 2026-07-23: 5Active Exploitation · 2026-07-26: 2Active Exploitation · 2026-07-30: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-09-16: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-07-22: 6Patch / Workaround · 2026-07-23: 2Patch / Workaround · 2026-07-24: 1Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-22: 1Technical Details · 2026-06-10: 1Technical Details · 2026-07-21: 5Technical Details · 2026-07-22: 6Technical Details · 2026-07-23: 4Technical Details · 2026-07-24: 1Technical Details · 2026-07-26: 1Technical Details · 2026-07-29: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-18: 1Technical Details · 2026-09-16: 102-1902-2206-1007-2107-2207-2307-2407-2607-2907-3008-0308-0408-1308-1809-1610-08
Signal classification5 categories
Active Exploitation
2066.7%
Disclosure
413.3%
Patch
413.3%
Exploit
13.3%
General
13.3%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-191
Exploit1
2026-02-221
Disclosure1
2026-06-101
Active Exploitation1
2026-07-216
Active Exploitation5General1
2026-07-226
Active Exploitation4Patch2
2026-07-235
Active Exploitation4Patch1
2026-07-241
Patch1
2026-07-262
Active Exploitation2
2026-07-291
Disclosure1
2026-07-301
Active Exploitation1
2026-08-031
Active Exploitation1
2026-08-041
Disclosure1
2026-08-131
Active Exploitation1
2026-08-181
Disclosure1
2026-09-161
Active Exploitation1
Full discourse20 posts
  • Zero Day Engineering@zerodayalpha
    Active Exploitation

    ⚡️ 0-Day Alert: IBM LangFlow OSS RCE LangFlow agent orchestration deployments have been under active exploitation since May. CVE-2025-34291: CORS misconfiguration + SameSite=None CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist. Majority takes input from an API endpoint variable and executes it directly on the OS. Attack pattern suggests that LangFlow has not seen basic security QA from the developer, and shouldn't be deployed in environments where arbitrary code execution poses a risk. * Attached: 33017 patch diff and code trace to exec()

    Post summary

    IBM’s open‑source LangFlow platform is being actively exploited in production, with multiple CVEs offering unauthenticated RCE and IDOR; public PoCs exist and a patch diff is available.

    17022103.2K
    11.8K followersView on X
  • GreyNoise@GreyNoiseIO
    Active Exploitation

    Two CISA known-exploited remote code execution flaws in the AI application platform Langflow turned up this week inside ordinary commodity crawling. Adversaries attempted CVE-2025-3248 and CVE-2026-0770 at 3,968 and 4,770 connection attempts, both new to this brief series. Every address we recorded on either flaw also carries a generic web crawling tag, and roughly nine in ten collected environment files and enumerated WordPress installations alongside it. Two hosting providers supply roughly 95% of those addresses, so the source count measures provider egress. The same concentration ran through the rest of the week: four hosts carried 36% of all alternative-port SSH crawling observed, and one address carried more than half of the Remote Desktop crawling. Customers get the full weekly brief. Our public At The Edge one-pager: https://www.greynoise.io/resources/at-the-edge-clear-091426

    Post summary

    The text reports that two CISA KEV-listed remote code execution vulnerabilities in Langflow (CVE-2025-3248 and CVE-2026-0770) are being actively exploited, with adversaries attempting thousands of connection attempts, but no PoC code, named exploit tools, or remediation guidance is provided.

    0501511.3K
    29.6K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    ⚠️ CISA Warns of Actively Exploited Langflow RCE Vulnerability CISA has added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog after confirming active exploitation targeting Langflow, a visual framework used to build AI agents and workflows. * CVE-2026-0770 carries a critical CVSS score of 9.8 * The flaw enables unauthenticated remote code execution * Exploitation requires low complexity and no user interaction * The vulnerability affects the handling of the `exec_globals` parameter in Langflow’s validation endpoint * Successful exploitation may allow attackers to execute arbitrary code with root privileges * U.S. federal agencies have been directed to prioritize remediation Analyst Note: Internet-exposed AI development platforms can provide attackers with a direct path into sensitive infrastructure. Organizations using Langflow should immediately identify exposed instances, restrict access, review logs for suspicious validation requests, and apply available security updates or vendor mitigations. Sources: CISA KEV Catalog, NIST NVD, Trend Micro Zero Day Initiative #DDW #Intelligence #CyberSecurity #Langflow

    Post summary

    CISA confirms that CVE-2026-0770 is actively exploited, enabling unauthenticated remote code execution in Langflow with root privileges, and urges agencies to patch and remediate immediately.

    0501407.3K
    202.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-0770 - critical 🚨 Langflow < 1.3.0 - Remote Code Execution via validate_code() exec() > Langflow contains a remote code execution caused by inclusion of functionality from u... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-0770 @pdnuclei #NucleiTemplates ...

    Post summary

    CVE-2026-0770 is a critical remote code execution vulnerability in Langflow versions below 1.3.0, triggered via the validate_code() exec() function.

    01055296
    889 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    منصة Langflow لبناء AI Agents دخلت قائمة CISA KEV بسبب ثغرة CVE-2026-0770 الثغرة من نوع RCE تسمح لمهاجم بلا مصادقة بتنفيذ أوامر عن بعد بصلاحيات root سهولة تنفيذ الهجوم تجعل أي خدمة مكشوفة للإنترنت نقطة دخول مباشرة إلى السيرفرات والشبكة الداخلية https://t.co/Ahoi5vSEpn

    Post summary

    The post announces that Langflow’s CVE‑2026‑0770, an unauthenticated RCE with root privileges, has been added to the CISA KEV list, but offers no proof of exploitation, PoC, or patch details.

    120521.8K
    50.2K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz 🎯 Zafiyet Bilgisi Ürün: #Langflow Zafiyet: Güvenilmeyen Kontrol Alanından İşlev Dahil Edilmesi (Inclusion of Functionality from Untrusted Control Sphere) CVE: CVE-2026-0770 Zafiyet Türü: Inclusion of Functionality from Untrusted Control Sphere (CWE-829) Fidye Yazılımı İlişkisi: Şu an için bilinmiyor. 📌 Zafiyet Özeti Langflow üzerinde, Güvenilmeyen Kontrol Alanından İşlev Dahil Edilmesi (Inclusion of Functionality from Untrusted Control Sphere) zafiyeti tespit edilmiştir. Bu güvenlik açığı, uzaktaki bir saldırganın etkilenen Langflow kurulumlarında keyfi kod çalıştırmasına (Remote Code Execution - RCE) olanak tanıyabilir. Başarılı bir istismar sonucunda saldırgan, sunucu üzerinde yetkisiz kod çalıştırabilir, hassas verilere erişebilir, yapay zekâ iş akışlarını manipüle edebilir ve sistemi tamamen ele geçirebilir. 🛡️ Önerilen Aksiyonlar ✅ Güvenlik Güncellemeleri Langflow geliştiricileri tarafından yayımlanan güvenlik güncellemelerini ve önerilen hafifletici önlemleri (Mitigations) test ettikten sonra en kısa sürede canlı ortama uygulayın. ✅ Risk Yönetimi Süreçlerinizi CISA'nın BOD 26-04 (Risk Tabanlı Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Forensics Triage Requirements rehberlerine uygun şekilde yönetin. ✅ Erişim Kontrolleri İnternete açık Langflow sunucularını öncelikli olarak değerlendirin. Yönetim arayüzlerine erişimi yalnızca güvenilir ağlarla sınırlandırın. Güçlü kimlik doğrulama, ağ segmentasyonu ve erişim kayıtlarının sürekli izlenmesini sağlayın. ✅ Geçici Koruma Önlemleri Güvenlik güncellemesi veya önerilen hafifletici önlemler uygulanamıyorsa, Langflow servisini internetten izole edin veya yalnızca VPN üzerinden erişilebilir hale getirin. 📚 Referans: Langflow Security Advisory & CISA

    Post summary

    The bulletin announces CVE-2026-0770 in Langflow, explains RCE risks, and urges users to apply security updates and mitigations promptly.

    0304036
    525 followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    https://blog.kevintel.com/cve-2026-0770-exploited-in-the-wild-langflow-rce-added-to-cisa-kev/

    Post summary

    The blog confirms that CVE‑2026‑0770, a remote code execution flaw in Langflow, is actively exploited and has been added to the CISA KEV list, and it stresses applying vendor patches or mitigations.

    1102147
    61 followersView on X
  • cyber_updates_365@CyberUpdates365
    Active Exploitation

    Threat actors are exploiting the exec_globals parameter in Langflow's validate endpoint to achieve root-level RCE. Our analysis covers the CVE-2026-0770 exploit chain, ENCFORGE ransomware, and mandatory DevSecOps mitigations: https://cyberupdates365.com/cisa-orders-emergency-patch-for-critical-langflow-ai-framework-flaw/ #InfoSec #AppSec #MLOps

    Post summary

    Threat actors are exploiting the exec_globals parameter in Langflow’s validate endpoint to achieve root‑level RCE under CVE‑2026‑0770, and an emergency patch has been issued by CISA.

    0103081
    17 followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    CISA added Langflow CVE-2026-0770 to KEV. Before that, KEVIntel observed 137 RCE attempts from 46 IPs targeting /api/v1/validate/code. Traffic overlaps with CVE-2025-3248. Same endpoint, different bugs, ambiguous attribution. Full analysis in comments.

    Post summary

    The post reports that CVE-2026-0770 is being actively exploited, with 137 RCE attempts observed from 46 IPs.

    10030150
    61 followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    Top KEVs hitting KEVIntel sensors this week: 1. CVE-2021-41773 - 732 2. CVE-2022-47945 - 466 3. CVE-2025-55182 - 337 4. CVE-2026-0770 - 178 5. CVE-2026-63030 - 113 2,497 exploitation attempts from 500 source IPs across our sensors. Patch what attackers are actually exploiting.

    Post summary

    The post lists the top KEVs with significant exploitation attempts detected across sensors, indicating that these vulnerabilities are actively being used in the wild.

    1001094
    41 followersView on X
  • Shmoopy@BLACKMAN6990
    Patch

    CISA adds critical Langflow AI framework RCE (CVE-2026-0770) to the Known Exploited Vulnerabilities catalog. Federal agencies are ordered to patch under BOD 26-04. Review our technical guide on mitigating AI pipeline attacks: https://cyberupdates365.com/cisa-orders-emergency-patch-for-critical-langflow-ai-framework-flaw/ #CyberSecurity #CISA

    Post summary

    CISA announces CVE‑2026‑0770 as a critical RCE in the Langflow AI framework, adds it to the Known Exploited Vulnerabilities catalog, orders federal agencies to apply the patch per BOD 26‑04, and provides a technical guide for mitigation.

    0002056
    7 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    CISA added four flaws to its KEV catalog, including WordPress RCE (CVE-2026-63030) and Langflow RCE (CVE-2026-0770). All are exploited in the wild. #CISA #KEV #WordPress #Langflow #DDWRT #RCE #SQLInjection http://securityonline.info/cisa-kev-four-exploited-vulnerabilities/

    Post summary

    CISA’s KEV lists four CVEs, including WordPress and Langflow RCEs, all currently being actively exploited in the wild.

    00020464
    12.9K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    AIアプリ開発向けオープンソースプラットフォーム「Langflow」の未修正脆弱性CVE-2026-5027が実際に悪用されていることが確認された。VulnCheckによると、この脆弱性はパストラバーサルの問題で、攻撃者が任意の場所へファイルを書き込める可能性がある。 この脆弱性はTenableが発見したもので、POST /api/v2/filesエンドポイントがアップロード時のfilenameパラメータを適切に検証していないことに起因する。攻撃者は「../」を含むパストラバーサル文字列を利用し、ファイルシステム上の任意の場所へファイルを書き込むことができる。 VulnCheckのCaitlin Condon氏によると、この問題はリモートコード実行につながる可能性がある。また、Langflowではデフォルト設定で認証不要の自動ログイン機能が有効になっているため、攻撃者は認証情報なしで脆弱なエンドポイントへ到達でき、単一のリクエストで有効なセッショントークンを取得できるという。 現在確認されている攻撃では、対象システムへテスト用ファイルを書き込む活動が行われている。Censysのデータによると、インターネット上には約7,000のLangflowインスタンスが公開されており、その多くは北米に存在する。 Langflowでは今年に入り、CVE-2026-0770、CVE-2026-33017、CVE-2026-21445、CVE-2025-34291など複数の脆弱性が攻撃対象となっている。記事によると、CVE-2025-34291はイラン系の国家支援グループ「MuddyWater」による悪用も確認されている。 https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html

    Post summary

    The post confirms that CVE-2026‑5027 in Langflow is actively exploited, allowing attackers to write files via a path‑traversal flaw and potentially achieve remote code execution, yet no PoC, patch, or mitigation is referenced.

    000201.1K
    14.6K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #AppSec 1⃣ Jellyfin RCE (CVE-2026-35033) https://www.sonarsource.com/blog/jellyfin-remote-code-execution 2⃣ Exploiting Langflow's validate_code() Endpoint for RCE (CVE-2026-0770) https://www.resecurity.com/blog/article/exploiting-langflows-validatecode-endpoint-for-remote-code-execution 3⃣ Cruising for Shells in Flowise: 6 RCEs https://www.elttam.com/blog/cruising-for-shells-in-flowise 4⃣ Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232

    Post summary

    The post lists four newly disclosed RCE vulnerabilities with links to detailed analysis and likely PoCs, but does not mention active exploitation, patches, or debunking.

    00001209
    3.3K followersView on X
  • TECHEPAGES@techepages
    Active Exploitation

    🚨 CISA Orders Urgent Patching of Actively Exploited Langflow RCE CVE-2026-0770 (critical) allows unauthenticated remote code execution as root in Langflow (AI agent framework). Already exploited in the wild since late June — attackers are probing for AWS creds, env vars & deploying malware. CISA added it to KEV catalog. Federal agencies must patch by Friday.

    Post summary

    CISA has issued an urgent patch directive for CVE-2026-0770 in Langflow, noting it is already actively exploited in the wild, and federal agencies must remediate immediately.

    0001062
    30 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA ordered urgent patching of CVE-2026-0770 in Langflow, a critical flaw enabling unauthenticated root RCE via validate and exec_globals. KEVIntel saw 220+ attacks from 64 IPs. #Langflow #CISA #AWS https://www.hendryadrian.com/cisa-orders-urgent-action-on-actively-exploited-langflow-rce-flaw/

    Post summary

    CISA has mandated urgent patching for CVE‑2026‑0770 in Langflow after discovering widespread active exploitation—over 220 attacks from 64 IPs—prompting immediate remediation.

    00010207
    4.5K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣ CVE-2026-25903: https://seclists.org/oss-sec/2026/q1/166 Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates 2⃣ CVE-2025-13176: https://labs.infoguard.ch/advisories/cve-2025-13176_eset-inspect_edr_local-privilege-escalation LPE in ESET Inspect EDR 3⃣ From BRICKSTORM to GRIMBOLT: https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines 0-Day 4⃣ CVE-2026-0770: https://github.com/affix/CVE-2026-0770-PoC Langflow Remote Code Execution 5⃣ JWT Authentication Bypass in OpenID Connect Authenticator for Tomcat https://insinuator.net/2026/02/jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/ 6⃣ CVE-2026-2329: https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/ Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones

    Post summary

    The post lists multiple CVEs along with links that expose proof‑of‑concept or exploit code, indicating the primary focus is on exploit availability rather than patches or false claims.

    10000217
    3.0K followersView on X
  • DailyCVE@dailycve

    🔴 Langflow, Remote Code Execution, #CVE-2026-0770 (Critical) -DC-Oct2026-2870 https://dailycve.com/langflow-remote-code-execution-cve-2026-0770-critical-dc-oct2026-2870/

    0000016
    239 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-0770: Langflow Remote Code Execution Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04tlnbc0

    Post summary

    The text announces a Remote Code Execution vulnerability in Langflow (CVE‑2026‑0770), outlining potential business impacts and recommended responses, but it contains no exploit code, patch notes, or evidence of active attacks.

    0000027
    33 followersView on X
  • SecEngCyGy@snypet86
    Active Exploitation

    CISA KEV: Langflow unauth RCE CVE-2026-0770 due Jul 24. validate endpoint exec_globals - code as root. CVSS 9.8. No auth. Patch to 1.9.0+. Inventory exposed AI flow builders; keep them off the open internet. https://nvd.nist.gov/vuln/detail/CVE-2026-0770 #CISA

    Post summary

    CISA has identified Langflow CVE-2026-0770 as a high‑risk unauthenticated RCE being actively exploited, with a patch available starting at version 1.9.0 and preventive guidance to keep exposed AI flow builders isolated.

    0000056
    23 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more