The AI Tool Someone Installed Is Holding Your Cloud Keys — and It Is Under Attack

CVE-2026-0768 (CVSS 9.8) allows remote code execution in Langflow, an AI app builder, and is being used to steal cloud and API keys.

Get Advisory Support
Critical CVE-2026-0768CVE-2026-66066

VulnCheck reports active exploitation of CVE-2026-0768, rated CVSS 9.8, an unauthenticated remote code execution flaw in Langflow, an open-source framework used to build AI applications and agent workflows. The flaw sits in the code validator of Langflow's custom component editor, which fails to properly validate a user-supplied string before using it to execute Python code, and the resulting code runs in the context of the root user. VulnCheck recorded more than 50 detections within a few hours on August 30, 2026, a number that reached 360 by September 1. The traffic originates primarily from Russia. What the attackers are doing is as important as the flaw itself: according to Caitlin Condon, vice president of threat research at VulnCheck, requests are querying environment variables including LANGFLOW_SUPERUSER, OPENAI_API, AWS_ACCESS and AWS_SECRET values, reading /root/.cache/langflow/secret_key, and checking .ssh access and .bash_history size. This is credential harvesting, not vandalism. VulnCheck reports that threat actors have exploited as many as twelve vulnerabilities across the AI stack since 2025, with more than 15,000 successful attempts involving CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027, and has observed follow-on activity that includes a Python credential harvester, proxy agents, SimpleHelp for remote access, disabling auditd to create a forensic blind spot, and enlisting hosts into cryptocurrency mining. Public vulnerability databases list Langflow releases up to 1.4.2 as affected; note that JFrog previously demonstrated that a Langflow release described as fixed for a separate flaw remained exploitable, so upgrading to the latest available release is safer than stopping at the first version labeled patched. Separately, VulnCheck reports active exploitation of CVE-2026-66066 in Ruby on Rails, rated CVSS 9.5 and nicknamed KindaRails2Shell, which allows an unauthenticated attacker to read arbitrary files and leak process secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens, ultimately enabling remote code execution. Exploitation requires the application to use libvips for Active Storage image processing and to accept image uploads from untrusted users, and VulnCheck states that a patched 8.1.3.1 server still executed the underlying deserialization gadget in its testing.

Recommended action: The first task is discovery, and it is a Shadow AI problem. Ask whether Langflow — or any AI application builder, agent framework, or workflow orchestrator — is running anywhere in your environment. These platforms rarely arrive through procurement. They arrive as a pilot on a spare server, a virtual machine a developer stood up to test an idea, a cloud instance charged to a departmental card. Ask your IT provider directly, and ask your analysts and developers directly, because the answers are often different. If you find one, get it off the public internet today: these tools belong behind a VPN or restricted to internal addresses, with authentication in front of them, regardless of patch level. Then assume the credentials are already gone. Rotate everything that instance could reach — AI provider API keys, AWS access and secret keys, the Langflow superuser password, database credentials, SSH keys, and anything else present in that host's environment — and review your cloud provider logs for use of those keys from addresses you do not recognize. Upgrade to the latest available Langflow release rather than the first version described as fixed. There is a governance lesson underneath the patch. AI development platforms are attractive targets precisely because they concentrate credentials for everything else: the cloud account, the data warehouse, the model provider, sometimes the electronic health record. Your AI usage policy should require that any AI platform be inventoried and approved before it is connected to production data or issued a credential, that every key it holds has a named owner and a rotation schedule, and that the platform is covered by your vulnerability management process like any other server. For covered entities, if such a platform handled ePHI or held credentials to systems that do, a suspected compromise starts your security incident procedures under 45 CFR §164.308(a)(6), and the platform itself belongs in your risk analysis under 45 CFR §164.308(a)(1). Separately, if your organization or a vendor runs a Ruby on Rails application that accepts image uploads from the public, raise CVE-2026-66066 with whoever maintains it this week.
Sources: VulnCheck research and statements from Caitlin Condon and Patrick Garrity, Zero Day Initiative advisory ZDI-26-034, JFrog Security Research on Langflow patch completeness, The Hacker News (September 1, 2026), BleepingComputer (September 1, 2026).

← All security bulletins

Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.

Worried about a bulletin above?

We can assess your exposure to the threats above and other active campaigns, and help you remediate quickly.

Request an Exposure Check