CRITICAL글로벌 · 취약점 · 2026년 9월 1일BleepingComputer
Critical Langflow 취약점 악용해 OpenAI 및 AWS 키 유출
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. The security issue received a critical severity rating and resides in the code validator of Langflow’s custom component editor. Threat intelligence company VulnCheck detected the activity on its honeypots in the U.K. that were targeted in at least 50 exploitation attempts over the weekend, with attack traffic originating primarily from Russia.
CVE-2026-0768 · CVE-2026-0770 · CVE-2026-33017 · CVE-2026-5027 +2