Langflow AI pipeline RCE flaws exploited in the wild, added to CISA KEV
What happened
Critical unauthenticated remote code execution flaws in Langflow, a popular AI agent and pipeline builder, were exploited within about a day of disclosure and drew attacks from hundreds of IPs. Several Langflow CVEs landed on CISA's Known Exploited Vulnerabilities list, and one campaign fed Langflow access into agent-driven ransomware.
Langflow is an open-source visual tool for building AI agents and retrieval pipelines, often run on internet-facing servers. The most serious flaw, CVE-2026-33017, sat in an endpoint meant to let anyone run public flows without logging in: it accepted attacker-supplied flow definitions and ran the Python code inside them with no sandbox, giving full control of the server with a single request. It was disclosed on 17 March 2026, and Sysdig saw attacks on its honeypots within about 20 hours, before any public exploit code existed; one attacker went on to steal the server's environment variables, where API keys and database passwords are typically kept. A first patch was incomplete, and only version 1.9.0 fully fixed it. Further Langflow flaws were added to CISA's list of exploited vulnerabilities in August, and one campaign used Langflow access as the entry point for AI-driven ransomware.
How it happened
Leaky AI product: Unsecured AI infrastructure. Software used to run AI systems was reachable from the internet without proper protection and was exploited.
The software involved works with many AI models, so no single model maker was involved. The product was Langflow, which is open source, a type of AI-powered app. Vulnerability IDs: CVE-2026-33017, CVE-2026-9198.
Impact
Data was exposed. Data involved: credentials. Many organizations were affected.
Severity is rated High, calculated from how far the incident reached and how sensitive the data was.
Was the AI at fault?
No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.
Status and timeline
Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.
It became public on 17 Mar 2026.
Langflow released fixes, and CISA added the flaws to its Known Exploited Vulnerabilities catalog, ordering US federal agencies to patch CVE-2026-33017 by 8 April 2026.