Vulnerabilities & Exploits · Web App Attack

Langflow Vulnerability Exploited Within 20 Hours

Attackers harvested keys and credentials from exposed instances. That access risks connected databases and potential software supply-chain compromise.

3 sources · Mar 20

CVE-2026-33017

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 8

Timeline

Sources

Part of the PlainSec briefing for 2026-03-21

Every edition of this story: Langflow Vulnerability Exploited Within 20 Hours

More from today