CVE
CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
Exploitation IoCs 5
Filename bhup.php
IP 103[.]207[.]14[.]220
IP 20
IP 45[.]207[.]216[.]55
IP 46
MITRE ATT&CK TTPs 11
T1059 T1059.004 T1070.004 T1083 T1105 T1135 T1190 T1210 T1505.003 T1552 T1619
Command and Scripting Interpreter
Execution
Unix Shell
Execution
File Deletion
Defense Evasion
File and Directory Discovery
Discovery
Ingress Tool Transfer
Command And Control
Network Share Discovery
Discovery
Exploit Public-Facing Application
Initial Access
Exploitation of Remote Services
Lateral Movement
Web Shell
Persistence
Unsecured Credentials
Credential Access
Cloud Storage Object Discovery
Discovery
Source Articles
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hackers are actively exploiting a high-severity unauthenticated path traversal vulnerability, CVE-2026-29059, in the open-source developer platform Windmill. The flaw exists in the 'get_log_file' endpoint, allowing attackers to read arbitrary files on the server by manipulating the filename parameter. A key target is the /proc/1/environ file to extract the SUPERADMIN_SECRET environment variable, which can enable superadmin authentication and arbitrary code execution if set. The vulnerability has been patched in Windmill 1.603.3, but exploitation attempts continue against exposed instances.
hacker-news Jul 22, 2026
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to urgently patch CVE-2026-0770, a critical remote code execution vulnerability in the Langflow AI framework. This flaw allows unauthenticated attackers to execute code as root via improper handling of the exec_globals parameter in the validate endpoint. Exploitation has been observed in the wild since June 27, with attacks focused on command execution, reconnaissance, and attempts to exfiltrate AWS credentials and environment variables.
bleeping-computer Jul 22, 2026
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA has added four actively exploited vulnerabilities in Adobe ColdFusion, Joomla Page Builder, and Langflow to its Known Exploited Vulnerabilities (KEV) catalog. Exploitation of these flaws, including path traversal and improper access control, has been observed in the wild, leading to remote code execution and unauthorized access. Attackers have deployed web shells and targeted AI orchestration platforms to steal credentials, with activity linked to opportunistic, financially motivated campaigns. Federal agencies are urged to patch by July 10, 2026.
hacker-news Jul 8, 2026