THREAT OPS › Threat News › Langflow and Rails Exploitation Raises Credential Risks
Langflow and Rails Exploitation Raises Credential Risks
<h1>Langflow and Rails Exploitation Raises Credential Risks</h1> <p>Attackers are exploiting two separate critical vulnerabilities affecting Langflow and Ruby on Rails. <strong>CVE-2026-0768</strong> allows unauthenticated attackers to execute Python code on affected Langflow deployments, while <strong>CVE-2026-66066</strong> can expose files and application secrets through Rails Active Storage.</
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-0768cve
- CVE-2026-66066cve
- 7.2.3.2ipv4
- 8.0.5.1ipv4
- 8.1.3.1ipv4
Original source: https://socradar.io/blog/langflow-ruby-on-rails-flaws-exploited/