July 1, 2026
- Langflow RCE (CVE-2026-33017, CVSS 9.3) is under active exploitation, with attackers scanning exposed AI-app endpoints to drop a Monero miner via a single unauthenticated POST. The Hacker News, Dark Web Informer · Vulnerabilities & Exploits
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread