
4/ • The Impact: Attackers use simple ../ sequences to bypass constraints and drop malicious cron jobs straight onto the host. Active in-the-wild exploitation is happening right now. 2. LangGraph Memory Injection (CVE-2026-28277 / CVE-2025-67644)**
Post summary
The text confirms that CVE-2026-28277 and CVE-2025-67644 are currently being exploited in the wild through simple directory traversal attacks that deploy cron jobs, with no PoC or patch information provided.



