CVE

CVE-2026-9198

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

Exploitation IoCs 3

GitHub Repo Hermes Agent
GitHub User KnYuan
GitHub User knaithe

MITRE ATT&CK TTPs 6

Source Articles

Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability, CVE-2026-0768, in Langflow, an open-source AI application framework, to steal sensitive credentials including OpenAI and AWS API keys. The flaw exists in the code validator of Langflow's custom component editor, allowing arbitrary Python code execution with root privileges. Attack activity has been observed on honeypots, primarily originating from Russia, with over 360 exploitation attempts detected. Attackers query environment variables and sensitive files to harvest credentials and maintain persistence.
bleeping-computer Sep 1, 2026
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies of active exploitation of three critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat. The Langflow flaw (CVE-2026-9198) allows unauthenticated remote code execution by chaining API endpoints, with proof-of-concept exploits publicly available. A second Langflow vulnerability (CVE-2026-0770) is also being exploited for root-level remote code execution. The N-central vulnerability (CVE-2026-18576) enables attackers to hijack administrative accounts without authentication, despite prior patching attempts. The Apache Tomcat flaw (CVE-2026-34486), stemming from an incomplete fix for a prior encryption issue, is being exploited by a Chinese-speaking threat actor to deploy reverse shells. CISA has added all three CVEs to its Known Exploited Vulnerabilities catalog and mandated mitigation within three days.
bleeping-computer Aug 5, 2026
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. These include a critical remote code execution flaw in Langflow (CVE-2026-9198), a sensitive data encryption bypass in Apache Tomcat (CVE-2026-34486), and an authentication bypass in N-able N-central (CVE-2026-18556 and CVE-2026-18577). Exploitation of CVE-2026-34486 has been linked to a Chinese-speaking threat actor using the aliases knaithe and KnYuan, who leveraged AI-powered offensive tools like DeepSeek via the Hermes Agent framework to autonomously target internet-exposed systems. The actor combined autonomous reconnaissance with manual exploitation of known vulnerabilities in Citrix NetScaler, Marimo, and IKE VPN, among others, targeting over 460 organizations.
hacker-news Aug 5, 2026