CVE-2026-33017
Known exploited · CISA KEV
CISA federal remediation date Apr 8
Vulnerabilities · 179 days ago
Exploit achieved unauthenticated remote code execution roughly 20 hours after disclosure.
Known exploited · CISA KEV
CISA federal remediation date Apr 8
3 sources covering this story
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
Langflow CVE-2026-33017 exploited in 20 hours after disclosure, enabling RCE via exec(), exposing systems before patching cycles.
Hackers Exploit Critical Langflow Bug in Just 20 Hours
Sysdig details how threat actors exploited a critical CVE in Langflow in less than a day
Critical Langflow Vulnerability Exploited Hours After Public Disclosure
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.
Part of the PlainSec briefing for 2026-03-26