Attackers exploit unpatched Langflow flaw CVE-2026-5027 to run code on exposed AI workflow servers

Attackers are exploiting a security hole in Langflow that can let outsiders take over internet-exposed servers without logging in. The flaw, CVE-2026-5027, is an unauthenticated remote-code-execution bug affecting Langflow, an open-source tool for building AI workflows; exploitation means attackers can send crafted requests to run their own commands on vulnerable systems, and the article says no patch is available yet.
Why it matters: Organizations using Langflow should treat this as urgent because an exposed server could be fully compromised with no valid account needed. If you run Langflow, restrict internet access, apply any vendor mitigations, monitor for compromise, and patch immediately once a fix is released.

Sources

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Ionut Arghire 2026.07.08 46% relevant
This article references ongoing Langflow exploitation but for a different underlying flaw, adding that attackers chained the newer KEV-listed CVE-2026-55255 with the earlier Langflow RCE bug CVE-2026-33017 in observed attacks.
CISA orders feds to prioritize patching Langflow auth bypass flaw
Sergiu Gatlan 2026.07.08 77% relevant
This updates the broader ongoing Langflow exploitation story by adding a separate actively exploited flaw, CVE-2026-55255, that CISA has now placed in the KEV catalog with a federal patch deadline. It also ties current Langflow exploitation to prior abused flaws including CVE-2025-3248 and references financially motivated post-compromise activity targeting compute and credentials.
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
info@thehackernews.com (The Hacker News) 2026.07.08 78% relevant
This article adds that CISA has now formally added Langflow CVE-2026-5027 to the Known Exploited Vulnerabilities catalog, confirming active exploitation at the federal-priority level and raising urgency for exposed Langflow deployments.
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
info@thehackernews.com (The Hacker News) 2026.06.30 96% relevant
This is the same underlying event: exploitation of the unpatched Langflow RCE flaw CVE-2026-5027 on internet-exposed AI workflow servers. The new detail is that attackers are now deploying Monero cryptomining malware on compromised endpoints, showing concrete post-exploitation activity and impact.
Hackers Exploit Langflow Vulnerability for Remote Code Execution
Ionut Arghire 2026.06.11 98% relevant
This article is a direct update on the same Langflow event, adding VulnCheck's confirmation of in-the-wild exploitation, details that attackers used the vulnerable POST /api/v2/files endpoint plus default unauthenticated auto-login to get a session token, and an estimate of roughly 7,000 internet-accessible instances.
Path traversal flaw in AI dev platform Langflow exploited in attacks
Bill Toulas 2026.06.10 95% relevant
This article updates the same underlying event by adding that exploitation of CVE-2026-5027 is being observed now, describing the bug as a path traversal in the file upload endpoint, noting arbitrary file write as the immediate impact, and pointing users to the latest Langflow release 1.10.0 while referencing prior fixes in langflow-base 0.8.3 and Langflow 1.9.0.
Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
info@thehackernews.com (The Hacker News) 2026.06.10 100% relevant
This article appears to be the initial report of active exploitation of CVE-2026-5027 in Langflow, and no existing tracked story covers this specific flaw or product.
← Back to all stories