The attacks on CVE-2026-0768 are the latest threats against the low-code AI development platform, which adversaries are flocking to this year.

Attackers are exploiting critical Langflow and Rails flaws; the Rails bug can expose files and secrets and ultimately enable code execution.

Hackers are exploiting CVE-2026-0768, a critical, unauthenticated remote code execution vulnerability in Langflow.