All incidents

Langflow RCE flaw (CVE-2026-33017) exploited to deploy Monero cryptominer

campaignopenJun 27, 2026 — Jul 30, 2026
Langflow RCE flaw (CVE-2026-33017) exploited to deploy Monero cryptominer

ATTACKERS have been exploiting a critical remote code execution flaw in Langflow to install a Monero cryptocurrency miner on exposed AI application endpoints, a campaign first observed on 27 June 2026 and still active as of 30 July 2026. The vulnerability, tracked as CVE-2026-33017, lets unauthenticated actors run arbitrary code on unpatched servers, leading to the deployment of a modified KORKERDS/MALXMR variant that mines cryptocurrency and spreads via stolen SSH credentials.

CVE-2026-33017 carries a CVSS score of 9.3 and affects the Langflow platform, allowing attackers to bypass login procedures and execute commands with the privileges of the Langflow service. Once inside, the malware drops a payload that modifies system settings to favour mining processes, disables certain security controls and creates persistence mechanisms to survive reboots. The worm component scans for other accessible Langflow instances and attempts to propagate using harvested SSH keys.

According to the detailed analysis from Trend Micro Trend Micro research, the infection chain begins with an unauthenticated request to the Langflow API that triggers the RCE flaw. The subsequent payload not only mines Monero but also attempts to kill competing malware and establishes a reverse tunnel for further command and control activity. Similar findings were highlighted by SecurityOnline.info SecurityOnline.info and echoed in coverage by The Hacker News The Hacker News.

The campaign fits into a broader trend where threat actors leverage AI‑related tooling for autonomous attacks, as noted in a Unit 42 report Unit 42 describing Chinese‑speaking actors using AI models to identify and exploit flaws without constant human oversight. While no specific group has been linked to the Langflow miner activity, the steady volume of scans and successful compromises indicates an organised effort taking advantage of delayed patching in AI development environments.

Defenders should prioritise applying the latest Langflow patch that addresses CVE-2026-33017, which is already available from the vendor. Any publicly exposed Langflow instances that are not essential for business operations ought to be taken offline or placed behind strict authentication gateways. Network segmentation can limit lateral movement, and outbound traffic to known mining pools should be blocked at the firewall level.

Continuous monitoring for unusually high CPU utilisation or frequent outbound connections to unfamiliar IP ranges can help detect mining activity early. SSH keys used for administrative access should be rotated regularly and any unused keys removed. Enforcing application allowlisting and maintaining up‑to‑date vulnerability scans across AI development pipelines will reduce the chance that similar flaws remain unnoticed and exploitable.

Intelligence briefing updated Jul 30, 2026

CVE-2025-68613 10.0 KEV CVE-2026-21858 10.0 CVE-2026-33017 9.3 KEV
Root sourcewww.trendmicro.com
Timeline Coverage

Swipe to explore timeline