A critical vulnerability, CVE-2026-0768, has been heavily exploited in the low-code AI development platform Langflow, marking a significant uptick in attacks. This remote code execution flaw, rated 9.8 on the CVSS, was first disclosed in January by Trend Micro's Zero Day Initiative. Since its discovery, exploitation has rapidly broadened, with reports of over 50 detections primarily from IPs in Russia, but now from multiple countries.
Researchers emphasize that attackers are engaging in reconnaissance, credential harvesting, and exploiting multiple vulnerabilities due to Langflow's growing use and the lack of security practices by developers. With an increase in attacks on Langflow and associated vulnerabilities, defenders are advised to limit exposure and enhance security measures to mitigate risks.