LIVE · cybersecurity feed
Live wire
vulnerabilityhigh

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]

zeroday.news · 10d ago

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. government agencies to patch a critical, actively exploited remote code execution (RCE) vulnerability in the Langflow visual framework for building AI agents. The flaw, identified as CVE-2026-0770, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on Tuesday, July 22, 2026, with federal agencies mandated to secure affected systems by Friday, in accordance with Binding Operational Directive (BOD) 26-04.

Trend Micro researchers discovered and reported CVE-2026-0770, describing it as a critical security flaw that allows unauthenticated attackers to achieve remote code execution as root with low complexity. The vulnerability resides in the handling of the `exec_globals` parameter within the `validate` endpoint, stemming from the inclusion of a resource from an untrusted control sphere. This allows an attacker to execute arbitrary code with root privileges.

Vulnerability intelligence firm KEVIntel first detected in-the-wild exploitation of CVE-2026-0770 on June 27. Since then, KEVIntel has recorded over 220 exploitation attempts originating from 64 distinct IP addresses. Analysis of these attacks indicates that malicious activity extends beyond simple vulnerability checks. Observed payloads include attempts to deploy malware and exfiltrate sensitive information such as AWS credentials, environment variables, and container metadata. Organizations operating Langflow are advised to review historical requests to `/api/v1/validate/code`, investigate host activity, restrict access to the validation functionality, and rotate any exposed credentials if successful execution cannot be definitively ruled out.

CISA emphasized that vulnerabilities of this nature are frequently leveraged by malicious cyber actors and pose significant risks to federal enterprises. Agencies are responsible for assessing the internet exposure of their assets and ensuring compliance with BOD 26-04 patching guidelines.

This is not the first time CISA has flagged Langflow vulnerabilities for active exploitation. The agency previously identified a missing authentication security issue (CVE-2025-3248) in May 2025, a code injection vulnerability (CVE-2026-33017) in March 2026, and an Insecure Direct Object Reference (IDOR) flaw (CVE-2026-55255) earlier in July. CISA also confirmed that CVE-2025-3248 is being exploited in ransomware attacks, with reports from cloud security company Sysdig indicating its use by the JadePuffer ransomware gang to dump Langflow PostgreSQL databases.

vulnerabilitypatchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.