Product1 distinct publisher3 min readPublished
VulnCheck logged more than 15,000 successful hits on decoy Langflow instances while eleven new flaws joined the exploited-in-the-wild list, on a product whose first deployment model expects to face the internet.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The value of a compromised Langflow host is in what it was handed on setup day. VulnCheck's point is that these projects usually hold compute, keys into systems with sensitive data, and exposure to other high-value systems [14], which makes a low-code builder worth more than a random web server on the same subnet. Both intruders on VulnCheck's decoys behaved accordingly: one extracted credentials and set up IRC command and control [15], the other mined Monero and then scanned outward for the next host [17]. VulnCheck reads both as financially motivated [18].
Part of the exposure is a product default. Langflow's first deployment model is meant to run as an internet-accessible service, and opening the project's MCP server gives outsiders a shareable playground where they drive the flow's chat input and read its output without installing anything or generating an API key [12]. What gets pitched as a demo link is what gets deployed as an unauthenticated front door to a process that holds the keys. VulnCheck notes that Langflow does publish security best practices and that plenty of new adopters likely skim past them [13].
The arithmetic here is simple. One known-exploited flaw before 2026, plus eleven more reported during the first half of the year, makes twelve [6], and eleven across roughly 26 weeks is a new exploited-in-the-wild Langflow bug about every two and a half weeks [7]. The 15,000-plus number needs care, because it counts successful attempts against instances VulnCheck deliberately stood up vulnerable [9][10]. It measures attacker traffic, not victims. Two of the three CVEs in that traffic carry 2026 identifiers and the third, CVE-2025-3248, is a year older [19], so nothing is aging out of the scanners.
The detection problem sits in one step. The mining crew switched off auditd, producing what VulnCheck calls a forensic blind spot, before dropping the .sysd payload and pivoting to scan for other targets [17]. The version of that incident anyone gets to investigate begins after the logs stop.
For whoever has to answer for a Langflow instance on Friday, the useful grid has two axes: whether the instance is reachable from the public internet without authentication, and whether the credentials inside it work anywhere outside a sandbox. Reachable with live keys is the canary configuration, and it is the only quadrant that needs attention this week. Unreachable with live keys is a rotation task on a normal schedule. Reachable with sandbox-only keys is the playground the docs describe, which holds up only if someone has actually checked the keys rather than assumed them. Unreachable with no live keys does not need a meeting. Counting the CVEs you have patched will tell you less than answering, per instance, what one compromised flow can reach: hundreds of hosts are still sitting out there active and vulnerable, most of them in the United States [11].
Ranked by verification strength, evidence, and original report placement.
Before 2026, evidence showed only one Langflow vulnerability known to be exploited in the wild.
In 2026, VulnCheck has seen 11 additional Langflow vulnerabilities targeted and reported as exploited in the wild.
Across confirmed exploitation attacks seen in VulnCheck Canaries targeting Langflow, VulnCheck observed more than 15,000 successful attempts leveraging CVE-2026-0769, CVE-2025-3248 and CVE-2026-5027.
Langflow is an open source project that bills itself as a platform for building and deploying AI-powered agents and workflows.
Langflow is known as one of the fastest growing open source low-code AI tools and was acquired by IBM in 2024 through its DataStax acquisition.
On GitHub, Langflow has over 399 contributors, 153,000 stars and 9,900 forks.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
science
OX Security says MCP command execution is a design choice, so server owners own the risk1 distinct publisher
security
Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success1 distinct publisher
product
Most of 19 audited MCP servers keep their context-injection surfaces out of the docs1 distinct publisher
build
Keycloak's metadata-document executor provisions clients that accept plain PKCE1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific enough to check, sourced from one instrument
The strong part is granular: three CVEs named in live traffic, a path-traversal-to-RCE chain, an unauthenticated HTTP request path, and artefacts like .sysd and disabled auditd that any defender could verify or fail to verify on their own hosts. The weak part is the headline. Eleven newly exploited flaws are asserted as a number and never enumerated, and all of it flows from VulnCheck's canaries, Target Intelligence, and half-year report with no outside corroboration and no word from Langflow or IBM.
Broad install base, quantified exposed tail
Two different kinds of uptake are on the table and both are numbered: 153,000 stars and nearly 10,000 forks for the project, and hundreds of live vulnerable hosts still answering on the internet with the heaviest cluster in the US. Attacker uptake is the more concrete of the two — 15,000-plus successful hits across three flaws. What nobody has counted is how many production Langflow deployments are internet-facing in the first place, which is the number that would turn exposure into a rate.
The counting flatters the headline
Fifteen thousand successful attempts sounds like a siege; the targets were machines VulnCheck left unpatched on purpose, and scanners hammer the same hole thousands of times. With no window, no canary count, and no list of the eleven flaws, the two biggest figures are shaped to impress rather than to be reproduced. Push the other way, though: the two intrusion chains are sober, unglamorous, and more alarming than the numbers — a fortnight of undisturbed credential theft and an attacker who turned off audit logging before doing the interesting part.
The sensor vendor is also the storyteller
VulnCheck sells exploit and vulnerability intelligence, and this post exists to show that intelligence working — it opens by pointing at the firm's own half-year report and closes asking you to register for a demo. Everything persuasive in it is proprietary: the canaries, the Target Intelligence host counts, the exploited-in-the-wild tally. Nothing here is fabricated-looking, but the commercial pull runs in exactly the same direction as the alarming reading of the data.
Coherent account, no second witness
Internally the story holds together — CVE vintages fit the timeline, the two campaigns behave the way commodity crews behave, and the technical detail is too specific to be casual invention. But we are one publisher deep on a self-interested account, the eleven-flaw core is unitemised, and the affected party has not been heard from. Enough to act on defensively, not enough to quote as settled fact.