CVE-2026-33017
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
Vulnerabilità ed exploit · Attacco ad app web
Tentativi di sfruttamento sono stati osservati entro 20 ore dalla pubblicazione dell'advisory. Fonti indicano esfiltrazione di chiavi e credenziali.
4 fonti · 27 mar
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
The Hacker News
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
originaleHelp Net Security
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation - Help Net Security
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
originaleDark Reading
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
originalePart of the PlainSec briefing for 2026-03-28
Every edition of this story: Langflow RCE Aggiunta al KEV di CISA