CVE-2026-33017
Known exploited · CISA KEV
CISA federal remediation date Apr 8
Vulnerabilities & Exploits · Web App Attack
Exploit achieved unauthenticated remote code execution roughly 20 hours after disclosure.
3 sources · Mar 20
Known exploited · CISA KEV
CISA federal remediation date Apr 8
The Hacker News
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
Langflow CVE-2026-33017 exploited in 20 hours after disclosure, enabling RCE via exec(), exposing systems before patching cycles.
originalInfosecurity Magazine
Hackers Exploit Critical Langflow Bug in Just 20 Hours
Sysdig details how threat actors exploited a critical CVE in Langflow in less than a day
originalSecurityWeek
Critical Langflow Vulnerability Exploited Hours After Public Disclosure
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.
originalPart of the PlainSec briefing for 2026-03-26
Every edition of this story: Langflow Flaw Enables Unauthenticated Remote Code Execution