Langflow, Rails flaws exploited for credential discovery
Threat actors are actively exploiting critical vulnerabilities in the AI development platform Langflow and the Ruby on Rails framework, shifting from initial testing to widespread credential discovery and system reconnaissance. The exploitation of these flaws, including a severe remote code execution vulnerability in Langflow, has escalated significantly in recent weeks. The most prominent threat involves CVE20260768, a critical vulnerability in Langflow with a CVSS score of 9.8. This flaw resides in the platform's code validator and allows unauthenticated attackers to execute arbitrary Python code with root privileges on vulnerable systems. Versions of Langflow up to 1.4.2 are affected. The vulnerability, initially disclosed by Trend Micro's Zero Day Initiative in January 2026, is now being actively exploited for reconnaissance and credential harvesting. Threat intelligence firm VulnCheck reported observing over 50 exploitation attempts within hours on August 30, 2026, with the number rising to approximately 360 by September 1, 2026.