CVE
CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
Exploitation IoCs 14
Domain unknown
Email e78393397[@]proton[.]me
Filename /.lockd
Filename HOW_TO_DECRYPT
Filename README_DECRYPT
Filename bhup.php
Filename encfile
Filename keyforge
Filename lockd
SHA-256 8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2
SHA-256 ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328
IP 103[.]207[.]14[.]220
IP 45[.]207[.]216[.]55
IP unknown
MITRE ATT&CK TTPs 19
T1027 T1055 T1059 T1059.003 T1059.004 T1068 T1071.001 T1078 T1082 T1083 T1105 T1190 T1195.001 T1210 T1486 T1499 T1505.003 T1552 T1619
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
Command and Scripting Interpreter
Execution
Windows Command Shell
Execution
Unix Shell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Ingress Tool Transfer
Command And Control
Exploit Public-Facing Application
Initial Access
Compromise Software Dependencies and Development Tools
Initial Access
Exploitation of Remote Services
Lateral Movement
Data Encrypted for Impact
Impact
Endpoint Denial of Service
Impact
Web Shell
Persistence
Unsecured Credentials
Credential Access
Cloud Storage Object Discovery
Discovery
Source Articles
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to urgently patch CVE-2026-0770, a critical remote code execution vulnerability in the Langflow AI framework. This flaw allows unauthenticated attackers to execute code as root via improper handling of the exec_globals parameter in the validate endpoint. Exploitation has been observed in the wild since June 27, with attacks focused on command execution, reconnaissance, and attempts to exfiltrate AWS credentials and environment variables.
bleeping-computer Jul 22, 2026
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
A new ransomware named ENCFORGE, attributed to the threat actor JADEPUFFER, is targeting AI model files through exploitation of a critical unauthenticated RCE vulnerability (CVE-2025-3248) in Langflow versions prior to 1.3.0. The attackers leverage the exposed Docker socket to escalate from container to host, deploying a custom-packed Go-based ransomware that encrypts AI-specific file types using AES-256-CTR and an embedded RSA-2048 public key. The ransomware avoids data exfiltration, instead relying solely on encryption, and leaves ransom notes with a Proton Mail contact reused from prior attacks, indicating campaign continuity.
hacker-news Jul 21, 2026
CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to urgently patch CVE-2026-55255, an authentication bypass vulnerability in the Langflow AI development platform. This flaw allows authenticated attackers to access other users' workflows by manipulating the /api/v1/responses endpoint with a victim's flow_id, enabling data theft and resource abuse. Exploitation in the wild has been observed since June 25, with attackers pursuing financial gain through compute resource hijacking and credential theft. CISA has also added related Langflow vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2025-3248 and CVE-2026-33017, exploited by ransomware actors.
bleeping-computer Jul 8, 2026
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA has added four actively exploited vulnerabilities in Adobe ColdFusion, Joomla Page Builder, and Langflow to its Known Exploited Vulnerabilities (KEV) catalog. Exploitation of these flaws, including path traversal and improper access control, has been observed in the wild, leading to remote code execution and unauthorized access. Attackers have deployed web shells and targeted AI orchestration platforms to steal credentials, with activity linked to opportunistic, financially motivated campaigns. Federal agencies are urged to patch by July 10, 2026.
hacker-news Jul 8, 2026