logo

Hackers Exploit Critical Langflow Bug in Just 20 Hours

ID: 0aef044b-2db8-5460-9e56-a66512bce082

STIX ID: report--0aef044b-2db8-5460-9e56-a66512bce082

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-03-20

Date Updated: 2026-04-22

...
...

Sysdig observed rapid in-the-wild exploitation of CVE-2026-33017 — an unauthenticated RCE in Langflow with CVSS 9.3 — where attackers built exploits from the advisory within ~20 hours, scanned for vulnerable instances, deployed custom Python exploit toolkits, and harvested keys and credentials leading to access to databases and potential supply-chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.