🔘 Vulnerability(cybersecuritynews.com): Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
✉ 01.09.2026 16:52:27 Abinaya
💻 Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry.
The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations.
VulnCheck observed exploitation attempts against its internet-facing Canary systems shortly after the vulnerability was added to its Known Exploited Vulnerabilities catalog.
CVE-2026-0768 is an unauthenticated remote code execution flaw in the code validator used by Langflow’s custom component editor. An attacker may be able to execute code on a vulnerable server without first authenticating.
The flaw was disclosed through Trend Micro’s Zero Day Initiative in January, and VulnCheck said no public proof-of-concept exploit was known at the time of the observed attacks.
The company initially recorded more than 50 detections, but the volume later increased to around 360 exploitation events. The malicious requests appeared to be designed to identify valuable credentials and access paths rather than immediately deploy ransomware or other destructive payloads.
Langflow RCE and Rails Vulnerability Exploited
Observed commands attempted to retrieve environment variables associated with Langflow administration, OpenAI APIs, and AWS cloud access.
Observed first-time exploitation of CVE-2026-0768 in Langflow (source: VulnCheck )
Attackers also tried to read Langflow’s local secret key file at /root/.cache/langflow/secret_key, inspect SSH access, and determine the size of .bash_history files. These checks could help an intruder identify administrator activity, stolen credentials, cloud resources, and possible routes for lateral movement.
VulnCheck said the Langflow traffic primarily originated from Russia and, at the time of reporting, targeted Canary systems located in the United Kingdom.
The activity adds to a growing pattern of exploitation targeting Langflow. Several other Langflow vulnerabilities have reportedly been added to VulnCheck’s KEV catalog during 2026.
Separately, researchers observed exploitation of CVE-2026-66066, a critical Ruby on Rails vulnerability described as an Active Storage file-read-to-RCE issue.
Active exploitation of CVE-2026-66066 (source: VulnCheck)
The attacks hit Canary systems in Singapore, Israel, and the United Kingdom. VulnCheck linked the activity to a single source IP address in France. At ...
#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news
https://cybersecuritynews.com/langflow-rce-and-rails-vulnerability-exploited/
read it on CSN:
https://csn.net4me.net/cyber_security_27904.html

Cyber Security News
Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
Two critical Langflow and Ruby on Rails flaws are being actively exploited for reconnaissance, secret harvesting, and potential remote code execution.
September 1, 2026 5