Telemetry from VulnCheck confirms a sharp escalation in the exploitation of Langflow, an AI framework acquired by IBM through DataStax in 2024. On August 30, 2026, the firm recorded over 50 Canary detections within hours. By September 1, 2026, that figure climbed to more than 360 cumulative detections. This activity centers on CVE-2026-0768, a CVSS 9.8 unauthenticated remote code execution (RCE) flaw in the platform’s code validator, initially disclosed as a zero-day by the Zero Day Initiative (ZDI) on January 9, 2026.
The persistence of this vulnerability is not an isolated event. Throughout 2026, 12 distinct Langflow CVEs have been exploited in the wild, including 11 new vulnerabilities and one identified prior to the start of the year. Across CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027, researchers have documented over 15,000 successful exploitation attempts. The framework, which maintains an ecosystem of over 153,000 GitHub stars, remains a primary target for automated campaigns.
Geographic analysis of internet-exposed hosts shows a significant concentration of vulnerable infrastructure within the United States. Other high-density regions include Germany, Malaysia, Brazil, and India. Attackers are leveraging this global footprint to execute two primary operational profiles: credential harvesting and cryptomining. In the former, adversaries target sensitive environment variables, including LANGFLOW_SUPERUSER, OpenAI API keys, and AWS access and secret keys. They also perform SSH probing and attempt to extract the Langflow secret_key from /root/.cache/langflow/secret_key, while simultaneously auditing .bash_history for further intelligence.
The cryptomining profile involves the deployment of XMR miners, the disabling of auditd to evade detection, and subsequent lateral movement within compromised networks. Caitlin Condon, vice president of threat research at VulnCheck, noted that “adversaries appear to be conducting a mix of reconnaissance and credential harvesting activities.” This assessment aligns with observations of attackers systematically querying system configurations to maximize the utility of their access. As previously detailed in our coverage of Langflow credential harvesting infrastructure, the persistence of these campaigns suggests a highly automated and opportunistic approach.
The exploitation of Langflow highlights a recurring pattern. AI frameworks are deployed with the implicit assumption that the software is hardened by default. When these assumptions fail, the frameworks are repurposed as credential-harvesting infrastructure. The reliance on these tools by developers and enterprises, combined with the rapid pace of vulnerability discovery, creates a persistent security gap. The 399+ contributors to the Langflow project face a continuous cycle of patching that has yet to outpace the speed of attacker adaptation.
The current threat landscape for Langflow is part of a wider trend of AI-centric infrastructure vulnerabilities. Previous analysis has tracked similar patterns in the DIVD Zammad breach, the Bitget $387.5M theft, and the exploitation of FortiMail CVE-2026-104286. The emergence of the Citrix NetScaler Platypus C2 infrastructure and the rate of AI vulnerability discovery reported by GTIG underscore the risks inherent in modern AI deployment pipelines.
