CVE-2026-33017
Known exploited · CISA KEV
CISA federal remediation date Apr 8
Vulnerabilities · 172 days ago
Exploitation attempts appeared within 20 hours of the public advisory and observers report exfiltration of keys and credentials.
Known exploited · CISA KEV
CISA federal remediation date Apr 8
4 sources covering this story
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
CISA: New Langflow flaw actively exploited to hijack AI workflows
The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agents.
Part of the PlainSec briefing for 2026-03-28