CVE-2026-33017
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
Vulnerabilità ed exploit · Attacco ad app web
Lo sfruttamento è avvenuto circa 20 ore dopo la disclosure della vulnerabilità (CVE-2026-33017). Il vendor ha pubblicato la versione 1.8.1.
3 fonti · 20 mar
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
The Hacker News
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
Langflow CVE-2026-33017 exploited in 20 hours after disclosure, enabling RCE via exec(), exposing systems before patching cycles.
originaleInfosecurity Magazine
Hackers Exploit Critical Langflow Bug in Just 20 Hours
Sysdig details how threat actors exploited a critical CVE in Langflow in less than a day
originaleSecurityWeek
Critical Langflow Vulnerability Exploited Hours After Public Disclosure
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.
originalePart of the PlainSec briefing for 2026-03-26
Every edition of this story: Langflow Sfruttata per RCE Non Autenticata 20 Ore Dopo Disclosure