Critical Langflow flaw exploited to steal OpenAI and AWS keys
September 1, 2026 · BleepingComputer · Severity: CRITICAL
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. The security issue received a critical severity rating and resides in the code validator of Langflow's custom component editor. Threat intelligence company VulnCheck detected the activity on its honeypots in the U.K. that were targeted in at least 50 exploitation attempts over the weekend, with attack traffic originating primarily from Russia. VulnCheck lead security researcher Caitlin Condon said that the activity intensified and the total number of observed attacks increased to 360 as of today. According to Condon, the attacker conducts reconnaissance and queries environment variables to harvest administrative credentials or superuser authentication keys for Langflow instances, AWS secrets, and OpenAI API keys. 📌 **Analyst Note:** This CVE is confirmed actively exploited in the wild. Apply patches immediately and monitor for indicators of compromise.
Key Takeaways
- CVE-2026-0768 is a critical unauthenticated RCE flaw in Langflow's custom component editor.
- Threat actors exploit it to steal OpenAI API keys, AWS secrets, and admin credentials.
- VulnCheck detected over 360 exploitation attempts, with attack traffic primarily from Russia.
- The vulnerability is actively exploited in the wild, targeting Langflow instances for credential theft.