logo

CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation

ID: da7a24a2-e6f5-54b1-9cd0-1131ee74488d

STIX ID: report--da7a24a2-e6f5-54b1-9cd0-1131ee74488d

Feed Name: Help Net Security

Threat Score
88/100

Date Published: 2026-03-27

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

CISA added two urgent entries to its Known Exploited Vulnerabilities catalog: a critical Langflow code-injection flaw (CVE-2026-33017) that was rapidly weaponized and used to exfiltrate keys/credentials, and a Trivy supply-chain compromise (CVE-2026-33634) attributed to TeamPCP that pushed malicious releases and credential-stealing malware, with downstream impacts including compromised LiteLLM packages; federal agencies are required to remediate, and vendors/security teams have published mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.