Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren't always the most exploited
ID: a45ff923-c335-54d1-967c-db825713bb5d
STIX ID: report--a45ff923-c335-54d1-967c-db825713bb5d
Feed Name: Sysdig Blog
On June 25, 2026 Sysdig observed a single operator actively exploiting Langflow vulnerabilities—CVE-2026-33017 (unauthenticated RCE, mass-exploited in the wild) and CVE-2026-55255 (cross-tenant IDOR)—using flow enumeration to obtain UUIDs, an IDOR-based prompt to exfiltrate credentials, and RCE waves to fetch a second-stage loader from 45.207.216.55:8084; the report includes timeline details, IoCs (source IP, JA4, loader URL, execution marker), and an analysis showing why the easier-to-spray RCE yields more attacker effort-to-yield than the higher-scored but harder-to-exploit IDOR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
