CVE-2026-0770 · Critical · CISA KEV

Langflow RCE: Critical Vulnerability Actively Exploited in the Wild

Threat Engine Auto-Feed · data current as of 2026-07-21

CVE-2026-0770 in Langflow allows remote attackers to execute arbitrary code due to an untrusted control sphere vulnerability. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, indicating a high probability of successful exploitation.

  • CVSS:
  • EPSS percentile: 0.95225
  • Exploitation pressure: 82/100 (Critical)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 95th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability stems from the inclusion of functionality from an untrusted control sphere. This means that the software incorporates or executes code or data from a source that it should not implicitly trust, allowing an attacker to inject and execute their own malicious code.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using Langflow in their technology stack, particularly those in financial services and technology sectors, are at heightened risk due to confirmed adversary targeting.
  • Enterprises with publicly exposed Langflow instances, or those with internal instances accessible to potentially compromised user accounts.

Misconfigurations that escalate it

  • Lack of strict input validation and sanitization for data processed by Langflow.
  • Insufficient network segmentation, allowing attackers to reach Langflow instances from less secure network zones.
  • Over-privileged service accounts or user accounts interacting with Langflow.

High-impact scenarios

  • Remote code execution on the Langflow server, leading to full system compromise.
  • Data exfiltration from the compromised server or connected systems.
  • Establishment of persistent access for further lateral movement within the network.
  • Disruption of Langflow-dependent services and potential impact on business operations.

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor Langflow server logs for unusual process execution or outbound network connections.
  • Implement endpoint detection and response (EDR) solutions on Langflow hosts to detect suspicious activity.
  • Regularly scan Langflow instances for known vulnerabilities and misconfigurations.

Contain

  • Isolate affected Langflow instances from the network to prevent further compromise.
  • Block suspicious IP addresses identified in attack attempts at the network perimeter.
  • Review and revoke any potentially compromised credentials associated with Langflow.

Patch

  • Apply the latest security patches and updates provided by Langflow's vendor immediately.
  • If a patch is not yet available, implement vendor-recommended mitigation strategies or workarounds.

Frontier verdict — Critical

This is a critical, actively exploited vulnerability (CISA KEV, EPSS 95th percentile) allowing remote code execution, demanding immediate patching and enhanced monitoring.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.