← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 1, 2026 · 13:52via Cyber Security News

Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability

Brief

Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry.

The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations.

VulnCheck observed exploitation attempts against its internet-facing Canary systems shortly after the vulnerability was added to its Known Exploited Vulnerabilities catalog.

CVE-2026-0768 is an unauthenticated remote code execution flaw in the code validator used by Langflow’s custom component editor. An attacker may be able to execute code on a vulnerable server without first authenticating.

Read more on Cyber Security News