logo

CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours

ID: f52847a0-80e4-5300-995f-2750720abd19

STIX ID: report--f52847a0-80e4-5300-995f-2750720abd19

Feed Name: Sysdig Blog

Threat Score
88/100

Date Published: 2026-03-19

Date Updated: 2026-05-01

...
...

## Executive summary Sysdig Threat Research observed active exploitation of a critical unauthenticated RCE in Langflow (CVE-2026-33017) within ~20 hours of public disclosure: attackers scanned, weaponized the advisory, executed payloads to run shell commands, harvested environment secrets and database credentials, and hosted stage-2 droppers and C2 infrastructure; the report provides timelines, IoCs (source IPs, C2/dropper IPs and URLs, interactsh callback domains), detection rules, and immediate mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.