CuraSec

Act active

Active Exploitation of Critical Langflow RCE and Ruby on Rails Flaws

2026-09-01 15:28 UTC · The Hacker News · read the source ↗ #rce#active-exploitation#web-frameworks
  • Engineer — Act: CVE-2026-0768 in Langflow is a CVSS 9.8 RCE running as root with a public PoC and confirmed active exploitation — patch or take Langflow offline immediately; also audit Rails deployments for CVE-2026-66066 exposure and apply the latest Rails patch given the 0.28 EPSS and available PoC.
  • SOC/IR — Act: Active exploitation includes credential-probing and C2 callback activity — hunt for anomalous outbound connections and lateral movement originating from Langflow or Rails app servers since these flaws became public, and build detections for post-exploitation behavior on those hosts.
  • Leader — Skip
  • Signals: CVE-2026-0768 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub · CVE-2026-66066 — CISA KEV: not listed, EPSS 0.28, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.