CRITICAL
Langflow RCE Flaw (CVE-2026-33017) Exploited to Deploy Monero Miner
Threat actors are exploiting CVE-2026-33017, a critical (CVSS 9.3) unauthenticated remote code execution vulnerability in Langflow, to deploy Monero cryptocurrency miners. The attacks target exposed Langflow AI application endpoints, indicating threat actors are actively scanning for and targeting internet-facing AI infrastructure. Organizations running Langflow should ensure instances are not exposed to the internet without authentication and apply available patches.