CVE

CVE-2026-0770

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability

Exploitation IoCs 5

Filename bhup.php
IP 103[.]207[.]14[.]220
IP 20
IP 45[.]207[.]216[.]55
IP 46

MITRE ATT&CK TTPs 11

Source Articles

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hackers are actively exploiting a high-severity unauthenticated path traversal vulnerability, CVE-2026-29059, in the open-source developer platform Windmill. The flaw exists in the 'get_log_file' endpoint, allowing attackers to read arbitrary files on the server by manipulating the filename parameter. A key target is the /proc/1/environ file to extract the SUPERADMIN_SECRET environment variable, which can enable superadmin authentication and arbitrary code execution if set. The vulnerability has been patched in Windmill 1.603.3, but exploitation attempts continue against exposed instances.
hacker-news Jul 22, 2026
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to urgently patch CVE-2026-0770, a critical remote code execution vulnerability in the Langflow AI framework. This flaw allows unauthenticated attackers to execute code as root via improper handling of the exec_globals parameter in the validate endpoint. Exploitation has been observed in the wild since June 27, with attacks focused on command execution, reconnaissance, and attempts to exfiltrate AWS credentials and environment variables.
bleeping-computer Jul 22, 2026
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA has added four actively exploited vulnerabilities in Adobe ColdFusion, Joomla Page Builder, and Langflow to its Known Exploited Vulnerabilities (KEV) catalog. Exploitation of these flaws, including path traversal and improper access control, has been observed in the wild, leading to remote code execution and unauthorized access. Attackers have deployed web shells and targeted AI orchestration platforms to steal credentials, with activity linked to opportunistic, financially motivated campaigns. Federal agencies are urged to patch by July 10, 2026.
hacker-news Jul 8, 2026