Skip to main content
CyberConfirmedHighDevelopingFeatured
7.6

Critical Langflow RCE exploited to steal OpenAI, AWS credentials

Threat actors are actively exploiting CVE-2026-0768, an unauthenticated remote code execution vulnerability in Langflow, to steal credentials, tokens, and keys from AI application environments. The attack targets OpenAI and AWS credentials, indicating a focused campaign against AI infrastructure. The full scope of affected organizations and data exfiltration remains unclear, but the exploitation of a critical flaw in a widely used open-source framework poses significant supply-chain risk.

BleepingComputerabout 5 hours agoengCredibility 56%View source

Score Breakdown

Mosaic Score7.6
Confidence0.7
Significance0.8
Source credibility0.6
Source

Related signals

8 found