09/03/2026, 17.47

Langflow Security Breach: Critical AI Platform Vulnerabilities Exploited

Hackers are targeting Langflow AI platforms via RCE and credential harvesting. Learn about the critical CVEs and how to protect your AI infrastructure.
Key points
  • Critical RCE vulnerabilities in Langflow allow unauthenticated attackers to execute Python code as root.
  • Threat actors, primarily from Russia, are harvesting AWS keys, OpenAI API tokens, and SSH credentials.
  • Over 15,000 successful attacks have been recorded across multiple vulnerabilities since 2025.
  • Immediate updates to Langflow version 1.11.2 or higher are required to mitigate these risks.

The rapid adoption of low-code AI orchestration tools has created a new, high-value target for cybercriminals. Langflow, a popular open-source platform used by entrepreneurs and developers to build, test, and deploy AI agents, is currently facing a wave of critical security breaches. Recent intelligence reveals that attackers are not just scanning for weaknesses but are actively exploiting these flaws to infiltrate cloud environments and steal sensitive corporate secrets.

The anatomy of a root-level breach

At the center of the current crisis is CVE-2026-0768, a vulnerability with a near-perfect CVSS severity score of 9.8. This flaw resides within the code validator of the custom component editor. Because the platform fails to properly validate user-supplied strings before they are processed for Python code execution, an unauthenticated attacker can trigger a Remote Code Execution (RCE) event.

The danger here is absolute: the exploit allows the attacker to execute arbitrary Python code in the context of the root user. In practical terms, this means a hacker can gain total control over the server hosting the AI agent, bypassing all standard authentication layers. This is not a theoretical risk; security firms have already observed this vector being used to establish persistence within compromised systems.

Russian actors and the hunt for API keys

The motivation behind these attacks is clear: credential harvesting. According to data from VulnCheck, threat actors—with traffic primarily originating from Russia—are using these vulnerabilities to conduct deep reconnaissance. They are not merely crashing systems but are surgically querying environment variables to extract the keys to the digital kingdom.

Targeted data includes OPENAI_API keys, AWS_ACCESS and AWS_SECRET credentials, and the LANGFLOW_SUPERUSER variable. By accessing the /root/.cache/langflow/secret_key and checking .bash_history, attackers can pivot from a single vulnerable AI instance to the broader cloud infrastructure of a company, potentially accessing private databases and proprietary AI models.

A systemic surge in AI platform targeting

The current exploitation of CVE-2026-0768 is part of a broader, accelerating trend. Before 2026, evidence of Langflow vulnerabilities being exploited in the wild was virtually non-existent. However, the landscape shifted abruptly this year. Security researchers have now identified 11 additional vulnerabilities that have been targeted by attackers.

The scale of the impact is significant. More than 15,000 successful attacks have been recorded leveraging three specific flaws: CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027. The geographical distribution of vulnerable hosts is global, with the highest concentrations found in the United States, Germany, India, Brazil, and Malaysia. This indicates that the appetite for AI-driven automation is outstripping the implementation of basic security hygiene across these markets.

From cryptomining to C2 command centers

The aftermath of a successful Langflow breach varies depending on the attacker's goal. In some instances, the platform is used as a gateway for financial gain through cryptomining. Attackers have weaponized CVE-2025-3248 to enlist compromised machines into XMR cryptocurrency miner botnets, often disabling auditd to create a forensic blind spot that hides their activity from system administrators.

In more sophisticated campaigns, the goal is long-term espionage. Researchers observed the use of CVE-2026-5027 to drop Python credential harvesters, proxy agents, and SimpleHelp for permanent remote access. This transforms a business's AI tool into a Command-and-Control (C2) node, allowing hackers to scan for further targets within the internal network.

The findings highlight increased threat actor interest in AI development platforms, which can provide access to sensitive credentials, cloud environments, and other connected systems.

Urgent mitigation and the Italian alert

The urgency of the situation has triggered warnings from national cybersecurity agencies. The Italian National Cybersecurity Agency (ACN) recently issued an alert AL05/260831/CSIRT-ITA, identifying eight new vulnerabilities. Of these, two are classified as critical and four as high, covering a range of threats from Privilege Escalation to Arbitrary File Read and Information Disclosure.

The affected versions are Langflow OSS 1.x, specifically all versions prior to 1.11.2. To secure their infrastructure, businesses must immediately update their installations to version 1.11.2 or later. Given that many of these platforms are deployed as containers or within cloud environments, administrators should also rotate all API keys and secrets that may have been exposed during the window of vulnerability.

Global business impact: USA, UK, and beyond

For entrepreneurs and CTOs in the USA and UK, this breach serves as a critical warning about the AI Supply Chain. Many companies are integrating low-code AI tools to accelerate time-to-market, often treating them as isolated productivity tools rather than core infrastructure. However, as these tools require high-level permissions to access LLMs and cloud storage, they become the weakest link in the security chain.

In the US, where the regulatory focus is shifting toward AI safety and security frameworks, a breach of this nature could lead to significant liabilities under data protection laws if customer data is leaked via harvested AWS keys. In the UK, where the government is promoting an innovation-friendly AI environment, the reliance on open-source tools like Langflow requires a more robust approach to vulnerability management.

The lesson for the global market is clear: AI agents are not just software; they are privileged identities. If an AI platform has the power to read your database or call your API, it must be defended with the same rigor as your primary firewall. The transition from prototype to production must include a security audit of the orchestration layer, or the very tools designed to drive efficiency will become the primary vectors for corporate espionage.

FAQ

Which versions of Langflow are affected by these vulnerabilities?

All Langflow OSS 1.x versions prior to 1.11.2 are affected.

What is the most dangerous vulnerability currently being exploited?

CVE-2026-0768 is particularly critical as it allows unauthenticated Remote Code Execution (RCE) with root privileges.

What specific data are attackers trying to steal from Langflow instances?

Attackers are targeting environment variables, including OpenAI API keys, AWS access and secret keys, and SSH credentials.

How can a company tell if their Langflow instance was compromised?

Signs include unusual outbound traffic to Russian or foreign IPs, the presence of unauthorized Python scripts, or the discovery of cryptomining software (XMR) on the server.


Sources: Acn ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Printable version
CLOSE X
Share this story
See also
cPanel Root Access Flaw: Critical CVE-2026-65643 Risks for Hosting
A critical vulnerability in cPanel & WHM (CVE-2026-65643) allows authenticated users to gain root control. Learn the risks and how to patch your serve…
03/09/2026 14:21
Visa Launches Autonomous AI Security Harness for Auto-Patching Code
Visa releases the Visa Vulnerability Agentic Harness (VVAH), an open-source AI system that finds and patches production code vulnerabilities without h…
02/09/2026 17:48
AI Agents as Cyberweapons: Aurora Ransomware Exploits Cursor AI
Russian-speaking Aurora ransomware operators used Cursor's AI agent to breach 10 companies, bypassing safety guardrails via social engineering prompts…
02/09/2026 07:54
OpenAI Pauses Astra: The First AI to Hit Critical Cyber Risk
OpenAI suspends Astra development after the model potentially reached the Critical cybersecurity threshold, capable of autonomous zero-day exploit cre…
01/09/2026 11:13
Microsoft Edge Vulnerability and the Rise of Bug Bounty Intelligence
A critical flaw in Microsoft Edge highlights the danger of NTFS directory junctions. Explore how bug bounty write-ups are reshaping corporate security…
31/08/2026 17:45


In evidenza
Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now

ISCRIVITI A GLACOM.NEWS

I dossier su AI, tech e business che contano, nella tua email. Gratis.