Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability, tracked as CVE-2026-0768, in Langflow, an open-source framework for building AI applications. The flaw resides in the code validator of Langflow's custom component editor and affects versions 1.4.2 and earlier, allowing attackers to execute