The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert for U.S. government agencies, instructing them to prioritize patching actively exploited vulnerabilities within the Langflow visual framework used for building AI agents.
The vulnerability, identified as CVE-2026-0770, poses a significant risk, allowing unauthenticated attackers to execute remote code as root with minimal effort.
Researchers from Trend Micro uncovered that “a specific flaw exists in the handling of the exec_globals parameter provided to the validation endpoint.” This issue arises from the inclusion of untrusted control area resources, enabling attackers to potentially execute code in a root context. Details can be found in the original advisory.
According to vulnerability intelligence firm KEVIntel, the first known exploitation of CVE-2026-0770 occurred on June 27th, with over 220 exploitation attempts being recorded from 64 unique IP addresses prior to its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog.
KEVIntel’s founder, Ryan Dewhurst, noted that the malicious activity related to CVE-2026-0770 extends beyond simple vulnerability checks; identified payloads have been known to deploy malware and attempt to extract AWS credentials, environment variables, and container metadata.
Dewhurst further stated, “Most activities involved command execution checks and system reconnaissance. Additionally, we observed attempts to download second-stage scripts and access environment variables, cloud metadata, and credential files.”
Recommendations for organizations using Langflow include: reviewing past requests to /api/v1/validate/code, auditing host activity, restricting access to validators, and rotating any exposed credentials if a successful exploitation cannot be excluded.

CISA Urges Immediate Action from Federal Agencies
CISA has formally added CVE-2026-0770 to its Known Exploited Vulnerabilities (KEV) catalog, directing all U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems by Friday, as mandated by Binding Operating Order (BOD) 26-04.
The agency emphasized that “these types of vulnerabilities represent frequent attack vectors for malicious cyber adversaries and pose considerable risks to federal enterprises,” as reported in a recent alert.
“Stakeholders are accountable for assessing the Internet exposure of each asset and ensuring compliance with BOD 26-04 patching directives,” CISA stated.
This is not the first time vulnerabilities within Langflow have been flagged; previous issues include an authentication vulnerability in May 2025 (CVE-2025-3248), a code injection flaw in March 2026 (CVE-2026-33017), and an insecure direct object reference (IDOR) vulnerability (CVE-2026-55255) noted earlier this month.
CISA also confirmed that CVE-2025-3248 has been exploited in ransomware attacks, following reports from cloud security firm Sysdig regarding its use by the JadePuffer ransomware collective to compromise Langflow PostgreSQL databases.
Security teams document only 54% of successful attacks and issue warnings on merely 14%. Most threats move undetected through the environment.
Picus’ whitepaper provides insights into testing your SIEM and EDR rules through breach and attack simulations to improve threat detection.
Source: www.bleepingcomputer.com




