CISA has ordered U.S. federal agencies to urgently patch CVE-2026-0770, a critical Langflow flaw that lets unauthenticated attackers achieve root remote code execution. KEVIntel reported active exploitation and observed attempts to deploy malware, steal AWS credentials, and collect environment variables and container metadata. #CVE-2026-0770 #Langflow #CISA #KEVIntel
Keypoints
- CVE-2026-0770 in Langflow allows unauthenticated root remote code execution.
- The flaw affects the validate endpoint through the exec_globals parameter.
- KEVIntel observed more than 220 exploitation attempts from 64 source IPs.
- Attackers also tried to deploy malware and steal AWS credentials and metadata.
- CISA ordered federal agencies to patch the issue by Friday under BOD 26-04.