Langflow CVE-2026-0768 exploited to steal OpenAI and AWS keys
Source headline: Critical Langflow flaw exploited to steal OpenAI and AWS keys
Intelligence Summary
Threat actors are exploiting an unauthenticated remote code execution vulnerability in Langflow. The flaw is tracked as CVE-2026-0768. Exploitation is being used to steal credentials, tokens, and keys. The stolen keys include OpenAI and AWS credentials. This matters because successful exploitation can lead to unauthorized access to sensitive services. Patch Langflow and review for any signs of exploitation tied to CVE-2026-0768.
Recommended Action
Check whether your Langflow deployment is affected by CVE-2026-0768 and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.