CVE

CVE-2026-33017

Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint

Exploitation IoCs 27

Domain api[.]deepseek[.]com
Domain code[.]newcli[.]com
Domain dashscope[.]aliyuncs[.]com
Domain unknown
Email e78393397[@]proton[.]me
Filename /.lockd
Filename /home/worker
Filename HOW_TO_DECRYPT
Filename README_DECRYPT
Filename bhup.php
Filename encfile
Filename fofoapi.py
Filename http.server
Filename keyforge
Filename langflow_poc.py
Filename lockd
Filename python3 -m http.server 8888
GitHub Repo Chocapikk/CVE-2026-21858
GitHub Repo oscar-mine/CVE-2026-33017
GitHub Repo qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC
GitHub User KnYuan
GitHub User knaithe
SHA-256 8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2
SHA-256 ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328
IP 103[.]207[.]14[.]220
IP 45[.]207[.]216[.]55
IP unknown

MITRE ATT&CK TTPs 34

T1021
Remote Services
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1046
Network Service Discovery
Discovery
T1055
Process Injection
Defense Evasion
T1059
Command and Scripting Interpreter
Execution
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1059.004
Unix Shell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1071.001
Web Protocols
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1090
Proxy
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1133
External Remote Services
Persistence
T1190
Exploit Public-Facing Application
Initial Access
T1195.001
Compromise Software Dependencies and Development Tools
Initial Access
T1203
Exploitation for Client Execution
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1485
Data Destruction
Impact
T1486
Data Encrypted for Impact
Impact
T1499
Endpoint Denial of Service
Impact
T1505.003
Web Shell
Persistence
T1552
Unsecured Credentials
Credential Access
T1566
Phishing
Initial Access
T1583
Acquire Infrastructure
Resource Development
T1584
Compromise Infrastructure
Resource Development
T1585
Establish Accounts
Resource Development
T1586
Compromise Accounts
Resource Development
T1587
Develop Capabilities
Resource Development
T1588
Obtain Capabilities
Resource Development
T1588.001
Malware
Resource Development
T1619
Cloud Storage Object Discovery
Discovery

Source Articles

Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability, CVE-2026-0768, in Langflow, an open-source AI application framework, to steal sensitive credentials including OpenAI and AWS API keys. The flaw exists in the code validator of Langflow's custom component editor, allowing arbitrary Python code execution with root privileges. Attack activity has been observed on honeypots, primarily originating from Russia, with over 360 exploitation attempts detected. Attackers query environment variables and sensitive files to harvest credentials and maintain persistence.
bleeping-computer Sep 1, 2026
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A China-based threat actor using the aliases 'knaithe' and 'KnYuan' has leveraged the DeepSeek AI model in conjunction with the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with minimal human intervention. The attacker configured Hermes to use DeepSeek as a reasoning engine, enabling it to autonomously discover vulnerabilities, select targets, download exploit code, and attempt exploitation — including targeting Langflow servers via CVE-2026-33017 and n8n instances using chained exploits CVE-2026-21858 and CVE-2025-68613. While the autonomous attacks failed to successfully compromise systems due to authentication requirements, the actor manually exploited CVE-2026-3055 in Citrix NetScaler to achieve three successful compromises, extracting memory and hunting for session cookies. This campaign demonstrates a functional end-to-end autonomous offensive capability that dramatically accelerates the attack lifecycle.
bleeping-computer Jul 31, 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
A Chinese-speaking threat actor using the aliases knaithe and KnYuan leveraged the open-source Hermes Agent framework, powered by DeepSeek as the primary reasoning model, to autonomously conduct cyberattacks. The actor issued initial commands via Telegram, after which the agent independently identified internet-facing systems, selected public exploits, and attempted exploitation without further input. The campaign targeted vulnerabilities in Langflow, n8n, Marimo, and Citrix NetScaler systems, with confirmed exploitation of CVE-2026-3055 and CVE-2026-39987, though only three systems were successfully compromised. The operation was exposed due to an unintentional HTTP server exposing configuration files, API keys, exploit scripts, and logs.
hacker-news Jul 31, 2026
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has launched an AI-powered autonomous hacking campaign leveraging the Hermes Agent framework with DeepSeek as a reasoning engine to exploit seven critical vulnerabilities in Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS, and Microsoft Windows IKE Extensions. The campaign uses AI models to autonomously conduct vulnerability assessment, target selection, and exploit generation, with command and control coordinated via Telegram. The actor also leverages publicly available AI tools like Claude Code, Codex, and Qwen Code to support operations. When initial exploitation fails, the system automatically searches for new critical CVEs using GitHub PoCs to prioritize attack surfaces.
hacker-news Jul 30, 2026
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 identified a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan who conducted an AI-enabled autonomous cyberattack campaign. The actor used the Hermes Agent framework with DeepSeek as the reasoning engine to autonomously enumerate vulnerabilities, acquire exploit code, and launch attacks without human intervention. They targeted multiple vulnerabilities including CVE-2026-33017 in Langflow and chained CVEs in n8n (CVE-2026-21858 and CVE-2025-68613), though exploitation attempts failed due to configuration requirements. Manual operations successfully exploited CVE-2026-3055 in Citrix NetScaler, leading to confirmed data exfiltration. The campaign was exposed when the actor accidentally exposed their infrastructure via an HTTP file server.
unit42 Jul 30, 2026
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated U.S. federal agencies to urgently patch CVE-2026-0770, a critical remote code execution vulnerability in the Langflow AI framework. This flaw allows unauthenticated attackers to execute code as root via improper handling of the exec_globals parameter in the validate endpoint. Exploitation has been observed in the wild since June 27, with attacks focused on command execution, reconnaissance, and attempts to exfiltrate AWS credentials and environment variables.
bleeping-computer Jul 22, 2026
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
A new ransomware named ENCFORGE, attributed to the threat actor JADEPUFFER, is targeting AI model files through exploitation of a critical unauthenticated RCE vulnerability (CVE-2025-3248) in Langflow versions prior to 1.3.0. The attackers leverage the exposed Docker socket to escalate from container to host, deploying a custom-packed Go-based ransomware that encrypts AI-specific file types using AES-256-CTR and an embedded RSA-2048 public key. The ransomware avoids data exfiltration, instead relying solely on encryption, and leaves ransom notes with a Proton Mail contact reused from prior attacks, indicating campaign continuity.
hacker-news Jul 21, 2026
CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to urgently patch CVE-2026-55255, an authentication bypass vulnerability in the Langflow AI development platform. This flaw allows authenticated attackers to access other users' workflows by manipulating the /api/v1/responses endpoint with a victim's flow_id, enabling data theft and resource abuse. Exploitation in the wild has been observed since June 25, with attackers pursuing financial gain through compute resource hijacking and credential theft. CISA has also added related Langflow vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2025-3248 and CVE-2026-33017, exploited by ransomware actors.
bleeping-computer Jul 8, 2026
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA has added four actively exploited vulnerabilities in Adobe ColdFusion, Joomla Page Builder, and Langflow to its Known Exploited Vulnerabilities (KEV) catalog. Exploitation of these flaws, including path traversal and improper access control, has been observed in the wild, leading to remote code execution and unauthorized access. Attackers have deployed web shells and targeted AI orchestration platforms to steal credentials, with activity linked to opportunistic, financially motivated campaigns. Federal agencies are urged to patch by July 10, 2026.
hacker-news Jul 8, 2026