Langflow's code-validator flaw is being exploited to lift OpenAI and AWS keys
VulnCheck said attackers are exploiting CVE-2026-0768 in the code validator inside Langflow's custom component editor, affecting version 1.4.2 and earlier, without requiring a login. Its honeypots in the United Kingdom logged at least 50 attempts over one weekend, a count that grew to 360 attacks, with the traffic coming mainly from Russia. The requests hunt LANGFLOW_SUPERUSER credentials, OpenAI API keys and AWS secrets. Users are told to move to version 1.11.6, which closes this flaw along with other Langflow issues exploited during 2026.
Artificial Intelligence··Night
Langflow CVE-2026-0768 is being exploited without a login
VulnCheck said attackers are exploiting CVE-2026-0768, the unauthenticated flaw in the code validator inside Langflow's custom component editor. SecurityWeek gives the same flaw a CVSS score of 9.8 and writes that an unauthenticated attacker can execute arbitrary Python code as root. The flaw was reported through Trend Micro's Zero Day Initiative in July 2025 and publicly disclosed as a zero-day in January 2026. Langflow releases through version 1.4.2 are affected.[1], [2]
Langflow honeypots saw 360 attacks hunting OpenAI and AWS keys
VulnCheck's honeypots in the United Kingdom logged at least 50 exploitation attempts over one weekend; the count grew to 360 attacks, and SecurityWeek puts the United Kingdom canary total at over 360. The traffic came mainly from Russia. BleepingComputer writes that the requests read environment variables looking for LANGFLOW_SUPERUSER credentials, OpenAI API keys and AWS secrets. SecurityWeek adds that the same canaries saw queries for environment variables, secret keys and SSH access.[1], [2]
Langflow users are told to move to version 1.11.6
Trend Micro's Zero Day Initiative documented the same issue, which it describes as a missing validation of a user-supplied string before that string is used to execute Python code. Users are told to move to version 1.11.6, which closes this flaw along with the other Langflow issues exploited during 2026. VulnCheck said that before 2026 only one Langflow vulnerability was known to be exploited in the wild, and that in 2026 it has seen 11 additional vulnerabilities targeted. The same firm also reported more than 15,000 attacks successfully exploiting Langflow instances vulnerable to CVE-2026-0769, CVE-2025-3248 and CVE-2026-5027.[1], [2]