September 2, 2026
- Langflow CVE-2026-0768 (CVSS 9.8) is under active exploitation for unauthenticated Python execution as root, with observed activity focused on harvesting OpenAI and AWS API keys from the low-code AI platform (BleepingComputer). VulnCheck ties the same campaign cluster to exploitation of a critical Rails flaw for credential probing and C2 (The Hacker News).
· Exploited in the Wild
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
August 12, 2026
in When the AI Is the One Finding the Zero-Days
August 7, 2026
- N-able N-central attackers are persisting via Cloudflare Tunnels even after patching, per Gossi — check N-central servers for Cloudflare Tunnel traffic. CISA also added the auth-bypass (CVE-2026-18577) to KEV alongside Langflow and Tomcat (earlier coverage). Kevin Beaumont
· Vulnerabilities & Exploits
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
August 6, 2026
- CISA gave federal agencies three days to fix three actively exploited flaws, including the N-able N-central auth bypasses (CVE-2026-18556, CVE-2026-18577) (earlier coverage), a Langflow unauthenticated RCE (CVE-2026-9198, CVSS 9.8), and an Apache Tomcat flaw (BleepingComputer, The Hacker News). Horizon3 published attack-research validation for the N-central bypasses (Horizon3); the Langflow-based IBM agentic platform is separately reported under active attack (The Register).
· Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
August 3, 2026
- Langflow's
validate_code() endpoint can be abused for remote code execution on the AI flow-automation platform, Resecurity details — another reminder that the "build an agent workflow" tooling layer keeps shipping unauth RCE.
· Vulnerabilities & Exploits
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
July 23, 2026
- CVE-2026-0770 — Langflow RCE added to CISA KEV under active exploitation. The critical (CVSS 9.8) unauthenticated RCE in the popular AI-agent-building framework abuses the
exec_globals parameter in the validation endpoint; CISA ordered federal agencies to patch on an urgent timeline (BleepingComputer).
· AI & Model Security
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 18, 2026
- NadMesh Go botnet hunts exposed AI services for cloud keys — a Shodan-fed harvester targets ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio; the operator's dashboard claims 3,811 unique AWS keys and Kubernetes tokens (The Hacker News).
· Threat Activity
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 9, 2026
- CISA added actively-exploited Adobe ColdFusion (CVE-2026-48282), Langflow, and two Joomla extension flaws to its KEV catalog, giving federal agencies a Friday deadline. The Langflow auth bypass is the same flaw the LLM-driven JADEPUFFER operator exploited last week. BleepingComputer, The Hacker News
· Vulnerabilities & Exploits
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
July 3, 2026
- Sysdig says it captured the first documented case of agentic ransomware: an operator it dubs JADEPUFFER in which a large language model handled the entire chain — breaking into an internet-facing Langflow instance via CVE-2025-3248, stealing credentials, moving laterally, then encrypting and wiping a production database. Sysdig, The Hacker News.
· AI & Model Security
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire
July 1, 2026
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread