2 min read

CISA Sets Friday Deadline for Langflow RCE Patches

CISA has ordered U.S. federal agencies to patch the actively exploited Langflow flaw CVE-2026-0770 by Friday after in-the-wild attacks.

Image: BleepingComputer

CISA has ordered U.S. government agencies to urgently patch an actively exploited flaw in Langflow, the visual framework used to build AI agents. The bug, tracked as CVE-2026-0770, is a critical remote code execution vulnerability that lets unauthenticated attackers run code as root in low-complexity attacks.

According to Trend Micro, which discovered and reported the issue, the flaw sits in how the exec_globals parameter is handled by the validate endpoint.

“The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root.”

Trend Micro researchers

KEVIntel first saw in-the-wild exploitation of CVE-2026-0770 on June 27, recording more than 220 exploitation attempts from 64 unique source IP addresses before CISA added the bug to its Known Exploited Vulnerabilities catalog.

Ryan Dewhurst, KEVIntel’s founder, told BleepingComputer the attacks went beyond simple vulnerability probes. The observed payloads also tried to deploy malware and collect AWS credentials, environment variables, and container metadata.

Recommended reading

Estée Lauder took 11 months to reveal HR data breach

“Most activity involved command-execution checks or system reconnaissance. However, KEVIntel also observed attempts to download second-stage scripts and access environment variables, cloud metadata and credential files.” “Organizations operating Langflow should investigate historical requests to /api/v1/validate/code, review host activity, restrict access to the validation functionality and rotate exposed credentials where successful execution cannot be ruled out.”

Ryan Dewhurst, KEVIntel founder

On Tuesday, CISA formally added the flaw to its KEV catalog and told Federal Civilian Executive Branch (FCEB) agencies to secure affected systems by Friday, under Binding Operational Directive 26-04.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.” “Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.”

CISA

CISA has already flagged several other Langflow bugs as exploited in the wild: CVE-2025-3248 in May 2025, CVE-2026-33017 in March 2026, and CVE-2026-55255 earlier this month. The agency has also said CVE-2025-3248 is being used in ransomware attacks after Sysdig reported that the JadePuffer gang was exploiting it to dump Langflow PostgreSQL databases.

Article image
Article image
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

// Keep reading