Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys.

Attackers are exploiting critical Langflow and Rails flaws; the Rails bug can expose files and secrets and ultimately enable code execution.

Hackers are exploiting CVE-2026-0768, a critical, unauthenticated remote code execution vulnerability in Langflow.