Patched in January, Still Harvesting in October — CVE-2026-0768 and Langflow’s 12-CVE Exploitation Streak
Nine months after disclosure, a January zero-day in Langflow is still producing fresh victims. A 2 October 2026 analysis citing VulnCheck telemetry reports a sustained campaign built on CVE-2026-0768 — a CVSS 3.0 9.8 CRITICAL unauthenticated remote code execution flaw in Langflow's code validator, disclosed as a zero-day by the Zero Day Initiative on 9 January 2026 (ZDI-26-034) and published to NVD on 23 January. VulnCheck's Canary telemetry recorded over 50 detections within hours on 30 August, climbing past 360 cumulative detections by 1 September — a sevenfold jump in 48 hours. The same analysis counts 12 distinct Langflow CVEs exploited in the wild during 2026, with over 15,000 successful exploitation attempts documented across CVE-2026-0769, CVE-2025-3248 and CVE-2026-5027.
The NVD description is worth quoting because the flaw is so elemental: the code parameter handed to the /validate endpoint was executed as Python without proper validation, no authentication required, in the context of root. A public route that accepts raw source and execs it is not a subtle bug; it is a missing security boundary. NVD marks the record Analyzed. And yet this is the twelfth entry in a year-long exploitation ledger for a single framework — which tells you the patching problem was never about understanding any one CVE.
Two businesses run on the same access
Attackers are running two operational profiles off the same foothold. The first is credential harvesting: environment variables including LANGFLOW_SUPERUSER, OpenAI API keys and AWS access keys, the Langflow secret_key lifted from /root/.cache/langflow/secret_key, SSH probing, and .bash_history audits for further intelligence. The second is cryptomining: XMR miners, auditd disabled to blunt detection, then lateral movement. VulnCheck vice president of threat research Caitlin Condon characterises the mix as reconnaissance plus credential harvesting — attackers systematically querying system configuration to maximise the utility of access they already hold.
This dual monetisation is now the house pattern for AI-framework compromise. We documented Monero mining on AI servers via CVE-2026-33017, and the current campaign's credential-theft profile — cloud keys plus model API keys from one host — is what makes an agent-framework box more valuable than a generic web shell. A Langflow server holds the keys to the victim's cloud and the keys to their AI spend, and the .bash_history audit shows operators who know it. Geographic telemetry concentrates exposed hosts in the United States, with high density also in Germany, Malaysia, Brazil and India.
The streak is the story
Twelve exploited CVEs in one framework in nine months is not a vulnerability problem; it is a deployment-lifecycle problem. Langflow — the DataStax-originated visual LLM framework now inside IBM's portfolio, with an ecosystem the analysis pegs above 153,000 GitHub stars — ships fast, deploys with the implicit assumption it is hardened by default, and gets repurposed as credential-harvesting infrastructure each time that assumption fails. The JADEPUFFER Azure destruction campaign entered through CVE-2025-3248, a flaw patched in April 2025 and long since in CISA's KEV catalog — seventeen months before the ransomware. The CVE-2026-0768 activity follows the same curve: disclosed in January, weaponised at scale in late August, still being stitched into October threat reporting.
Google's threat-intelligence group tracked the structural side of this in September: AI-discovered flaws skew toward RCE, disclosures doubled, and agent-orchestration frameworks absorb a disproportionate share of attacker attention. The Langflow ledger is the case study — not because Langflow is uniquely negligent (its 399-plus contributors patch continuously) but because attacker adaptation now outruns any patch cycle that depends on operators upgrading stateful, internet-exposed AI infrastructure by hand.
What to do
- Patch past January, then verify the whole lineage. CVE-2026-0768 is nine months old, but twelve CVEs were exploited this year — closing one hole while CVE-2026-0769, CVE-2025-3248 or CVE-2026-5027 remains open leaves the same harvesting infrastructure in place. Inventory every Langflow instance, including desktop and knowledge-base deployments, against the full 2026 CVE list.
- Assume exposed instances are already harvested and rotate everything. The campaign's first profile is credential theft: rotate OpenAI keys, AWS keys,
LANGFLOW_SUPERUSERmaterial and the on-disksecret_key, and review.bash_historyand SSH logs for the reconnaissance the attackers perform before monetising. - Take Langflow off the public internet or gate it hard. Every one of these CVEs is unauthenticated and network-reachable. No agent-building UI needs a public IP; put it behind SSO/VPN, and treat
auditdtampering or unexpected XMR-stratum traffic as a compromise signal, not an anomaly. - Track exploitation telemetry, not just disclosures. The August 50-to-360 detection surge preceded October's reporting by a month. VulnCheck Canary-style honeypot telemetry and KEV additions are earlier signals than vendor advisories for frameworks with this exploitation tempo.
Our verification was documentary: we confirmed CVE-2026-0768 in NVD (Analyzed; CVSS 3.0 9.8 CRITICAL; unauthenticated Python execution via the validate endpoint's code parameter as root; ZDI-26-034), read the 2 October Forkast analysis in full, and checked the related CVE-2026-0769, CVE-2025-3248 and CVE-2026-5027 references against our existing coverage. The 50-to-360 detection figures, the 12-CVE count and the 15,000-attempt figure are Forkast's reporting of VulnCheck telemetry, attributed as such; we did not independently reproduce VulnCheck's sensor data. We sent no traffic to any Langflow instance.
Sources:
- Forkast — "Langflow's 12th Exploited CVE of 2026 Fuels Sustained Credential Harvesting Campaign" (Heath Callahan; 2 October 2026 12:59 UTC; VulnCheck telemetry 50 to 360 detections 30 August–1 September; 12 exploited CVEs; 15,000+ attempts)
- NVD — CVE-2026-0768 (published 23 January 2026; Analyzed; CVSS 3.0 9.8 CRITICAL; unauthenticated code injection via the validate endpoint's code parameter, execution as root; ZDI-CAN-27322)
- Zero Day Initiative — ZDI-26-034, Langflow code injection RCE (disclosed 9 January 2026 as zero-day)
- Help Net Security — "The vulnerabilities AI finds are the ones attackers want" (1 October 2026; GTIG figures including Langflow CVEs CVE-2026-5027 and CVE-2025-3248 among AI-era exploitation examples)