THREATOPS
THREAT OPSThreat News › Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

medthehackernewsPublished 2026-09-01

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.

The vulnerabilities in question are listed below -

CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html