Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave

Langflow unauthenticated RCE exploitation and secret theft

Updated 30.06.2026 18:47
Case score 64
Members 2 First seen 20.03.2026 12:20 Latest activity 30.06.2026 18:47

Overview

**CVE-2026-33017** in **Langflow** lets a remote attacker execute attacker-controlled Python code on exposed instances without authentication. Exploitation appeared within 20 hours of disclosure and quickly moved from scanning to custom scripts that targeted files, environment data, and secrets. The activity included credential theft, database and configuration access, and callback traffic to **173.212.205[.]251:8443**. CISA added the flaw to **KEV** with a remediation date of **2026-04-08**, so exposed Langflow deployments should be patched and checked for compromise immediately.
Latest development Open development history 2 earlier developments Sysdig observes early exploitation of CVE-2026-33017 Sysdig reports first exploitation attempts against CVE-2026-33017, saying attackers built working exploits directly from the advisory without public PoC code, moved from scanning to custom Python scripts, exfiltrated keys and credentials, and used 173.212.205[.]251:8443 to stage next-stage payloads.
  1. Earlier development

    Aviral Srivastava reports CVE-2026-33017

    Security researcher Aviral Srivastava discovers and reports CVE-2026-33017 in Langflow on February 26, 2026, identifying a critical flaw that would later be tied to unauthenticated remote code execution risk.

  2. Earlier development

    March 17 advisory discloses CVE-2026-33017 in Langflow

    A March 17 advisory disclosed CVE-2026-33017 in Langflow, an unauthenticated remote code execution flaw with CVSS 9.3 that lets attackers execute arbitrary Python code on exposed instances with a single HTTP request and no credentials.

Signals

Impact signals
Exploitation
CVEs/products
Remediation

Malware & tooling context

7 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Langflow missing-authentication code-injection flaw (CVE-2026-33017)
Updated 20.03.2026 17:15 Lead Contribution 61
Exploitation Active Exploitation Exploit No Known Public Exploit CVSS 9.8 Critical Patch Patch Available

**Langflow**'s **CVE-2026-33017** is being **actively exploited** to deliver a **Monero miner** through exposed **AI application endpoints**. The campaign uses **unauthenticated RCE** to run attacker-supplied Python, pull a shell script, drop **lambsys** and **XMRig**, kill competing miner processes, disable host defenses, and persist through cron and SSH reuse. Activity was observed over **19 days** from **March 27 to April 15, 2026**, showing continued abuse of the same flaw in fresh cryptomining attacks.

Exploitation Wave Langflow CVE-2026-33017 exploitation wave
Updated 20.03.2026 12:20 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.8 Critical

**CVE-2026-33017** in **Langflow** was disclosed on **March 17, 2026** as an unauthenticated **RCE** with **CVSS 9.3**, allowing arbitrary Python execution from a single HTTP request with no credentials. By **March 20**, **Sysdig** said attackers had already built working exploits from the advisory, scanned exposed instances, and stolen **databases**, **API keys**, **cloud credentials**, and **configuration files**. **CISA** later said the flaw was actively exploited in **Langflow 1.8.1 and earlier** and told federal agencies to patch or stop using the product by **April 8**. **Trend Micro** then reported a **March 27-April 15, 2026** campaign that used the same flaw to drop **lambsys** and **XMRig**, kill competing miners, and persist through **cron** and **SSH**.