CISA Mandates Federal Agencies Patch Actively Exploited Langflow AI Framework Flaw

CISA adds a critical vulnerability in the Langflow visual framework for building AI agents to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch their systems by Friday. Tracked as CVE-2026-0770, the flaw allows unauthenticated attackers to achieve remote code execution with root privileges through low-complexity attacks. Trend Micro researchers discover and report the vulnerability, which stems from improper handling of the exec_globals parameter in the validate endpoint.

Vulnerability intelligence firm KEVIntel first detects active exploitation on June 27, recording over 220 attempts from 64 unique IP addresses. Attackers go beyond simple vulnerability checks, deploying malicious payloads that attempt to install malware and harvest AWS credentials, environment variables, and container metadata. KEVIntel founder Ryan Dewhurst notes that observed activity includes command-execution checks, system reconnaissance, and efforts to download second-stage scripts.

CISA warns that this class of vulnerability represents a frequent attack vector that poses significant risks to the federal enterprise. Organizations running Langflow should investigate historical requests to the validation endpoint, review host activity, and restrict access to validation functionality. Dewhurst also strongly advises rotating any exposed credentials in cases where successful exploitation cannot be ruled out.

Read More at the original source →