Threat actors have begun exploiting a critical remote code execution (RCE) vulnerability in the Langflow low-code AI platform, vulnerability intelligence firm VulnCheck has warned.
Tracked as CVE-2026-0768 (CVSS score of 9.8), the security flaw exists within the code validator in Langflow’s custom component editor.
Because the user-supplied string is not properly validated before being used to execute Python code, an attacker could use the flaw to execute arbitrary code as root without authentication.
The security breach was reported via ZDI in July 2025 and was made public revealed as day zero in January 2026. All Langflow releases up to version 1.4.2 are affected.
According to VulnCheck, threat actors used the vulnerability to conduct reconnaissance and credential harvesting operations.
The Cyber Security Company monitored requests for environment variables, secret keys and SSH access, mainly originating in Russia. By Monday, VulnCheck had seen over 360 exploit attempts hitting its UK canaries.
Exploitation of CVE-2026-0768 in the wild is no surprise. Last week, VulnCheck warned of a recently observed increase in targeting the Langflow vulnerability.
“Prior to 2026, evidence showed only one Langflow vulnerability known to be exploited in the wild. In 2026, things changed rapidly. We have now seen 11 additional vulnerabilities targeted and reported as exploited in the wild, highlighting the growing interest of attackers in Langflow,” the company said.
VulnCheck has seen more than 15,000 attacks successfully exploiting Langflow instances vulnerable to three of the known exploited flaws, namely CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027.
Related: A critical vulnerability in JFrog Artifactory that is reported to be exploited in the wild
Related: WatchGuard fixes critical vulnerabilities
Related: PaperCut exploitation escalates to active intrusions
Related: Silent patches don’t stop attackers – they blind defenders