Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
14 articles

#Langflow

All CosmicBytez Labs articles tagged #Langflow, across news, security advisories, how-to guides, and projects.

  • NewsAug 5, 2026

    CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

    CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, 2026 — a critical Langflow RCE, an Apache Tomcat encryption flaw, and an N-able N-central authentication bypass — all confirmed under active exploitation with a federal patch deadline of August 7.

  • SecurityAug 4, 2026

    CVE-2026-9198: IBM Langflow Code Injection Vulnerability

    A critical unauthenticated code injection flaw in Langflow 1.0.0–1.10.0 allows attackers to chain two API endpoints to obtain a SUPERUSER token and execute arbitrary Python via exec(), achieving full RCE on AI pipeline servers.

  • NewsJul 21, 2026

    New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

    Sysdig researchers link a second Langflow server attack to JADEPUFFER, an AI-agent-driven threat operator now deploying ENCFORGE — a Go-based ransomware...

  • SecurityJul 18, 2026

    CVE-2026-13446: IBM Langflow Hardcoded Credentials (CVSS 9.8)

    IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hardcoded credentials used for inbound authentication and internal encryption, allowing...

  • NewsJul 8, 2026

    CISA Orders Feds to Prioritize Patching Langflow Auth Bypass Flaw

    CISA added CVE-2026-55255, a CVSS 9.9 IDOR authorization bypass in Langflow, to its Known Exploited Vulnerabilities catalog on July 7, ordering U.S....

  • NewsJul 6, 2026

    JadePuffer: The First Fully Autonomous LLM-Driven Ransomware Attack

    Security researchers at Sysdig have documented JadePuffer — an agentic threat actor powered entirely by a large language model that independently...

  • NewsJul 4, 2026

    Agentic AI Used to Conduct Ransomware Attack via Langflow Vulnerability

    Threat group JadePuffer leveraged an LLM agent to autonomously execute a multi-stage ransomware-style attack through a critical Langflow vulnerability,...

  • NewsJul 2, 2026

    AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

    Sysdig researchers documented the first fully autonomous AI-driven ransomware campaign, where threat actor JADEPUFFER used an AI agent to chain Langflow...

  • NewsJun 30, 2026

    Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

    Threat actors are actively weaponizing CVE-2026-33017, a critical unauthenticated RCE flaw in Langflow, to deploy a Monero miner via the lambsys...

  • NewsletterJun 30, 2026

    June 30 Digest: BlueHammer Zero-Day, Ransomware Goes Corporate, AI Supply Chain Risks & Nation-State ICS Threats

    A Microsoft Defender zero-day fuels ransomware before any patch exists; researchers dissect how syndicate groups run HR departments and tiered pricing;...

  • NewsJun 10, 2026

    Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks

    Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in Langflow, to write arbitrary files on exposed servers....

  • NewsJun 10, 2026

    Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

    A high-severity path traversal flaw (CVE-2026-5027, CVSS 8.8) in the AI application builder Langflow is being actively exploited with no patch available....

  • SecurityMay 22, 2026

    CVE-2025-34291: Langflow Origin Validation Error

    CISA adds CVE-2025-34291 to the Known Exploited Vulnerabilities catalog — an overly permissive CORS configuration combined with a SameSite=None refresh...

  • NewsMar 29, 2026

    CISA: New Langflow Flaw Actively Exploited to Hijack AI

    CISA has added CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in the Langflow AI framework, to its Known Exploited...