A critical vulnerability in Langflow, a low-code AI development platform, is being heavily exploited by attackers, marking the latest threat against this increasingly popular target. The remote code execution flaw, CVE-2026-0768, was initially disclosed in January and has since been observed being used to conduct reconnaissance, credential harvesting, and other malicious activities.
The attacks are affecting Langflow users worldwide, with attempts coming from IP addresses in multiple countries. According to Caitlin Condon, vice president of security research at VulnCheck, the vendor’s canary systems have detected over 50 exploitation attempts as of this morning. “We’ve seen a mix of reconnaissance and credential harvesting activities,” Condon noted in a LinkedIn post on Saturday.
Langflow is used by developers to design AI agents, and its low-code nature makes it accessible to a wide range of users. However, this also means that the platform has become an attractive target for attackers. “Langflow provides security best practices to reduce the attack surface, but those practices are likely brushed aside by many of the newly adopted,” Condon explained.
The exploitation activity is not limited to just reconnaissance and credential harvesting. VulnCheck researchers have observed automated scanning, exploitation for initial access, and post-exploitation activities such as lateral movement and Langflow source code exfiltration. Some of the activity even hinted at previously hidden threats to Langflow users, including a campaign that was conducted with Python scripts featuring Chinese-language comments.
The rise in attacks on Langflow is not surprising given its popularity and accessibility. In 2026 alone, VulnCheck has reported 11 additional vulnerabilities targeted and exploited in the wild. “In 2025, only one Langflow flaw had been exploited in the wild,” Condon noted. “Things have changed fast this year.”
The attention on Langflow is partly due to its design as Internet-accessible services, which provide access to MCP servers, compute resources, sensitive data, and high-value systems within enterprise networks. This makes it an attractive target for attackers looking to gain initial access or expand their cryptomining operations.
As the attacks on Langflow continue to rise, it’s essential for users to take security best practices seriously. While Langflow provides guidelines for reducing the attack surface, many newly adopted users may be overlooking these recommendations. “Adversaries are opportunistic and will exploit any vulnerability they can find,” Condon warned. “It’s crucial for users to stay vigilant and regularly update their systems to prevent exploitation.”
In light of this situation, we advise Langflow users to:
* Regularly review and apply security patches
* Implement robust access controls and authentication mechanisms
* Monitor system logs and activity for suspicious behavior
* Consider conducting regular vulnerability scans and penetration testing
Source: Dark Reading — 2026-09-01