CVE-2026-33017
Known exploited · CISA KEV
CISA federal remediation date Apr 8
Vulnerabilities & Exploits · Web App Attack
Exploitation attempts appeared within 20 hours of the public advisory and observers report exfiltration of keys and credentials.
4 sources · Mar 27
Known exploited · CISA KEV
CISA federal remediation date Apr 8
The Hacker News
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
originalHelp Net Security
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation - Help Net Security
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
originalDark Reading
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
originalPart of the PlainSec briefing for 2026-03-28
Every edition of this story: Langflow RCE Added to CISA Known Exploited Catalog