Six Langflow Bugs Were Exploited This Year. The One Being Used Today Was Disclosed in January.
CVE-2026-0768 is an unauthenticated root RCE in Langflow. It was disclosed in January, the fix has shipped through seven releases, and attackers are hitting it in September — because low-code AI middleware became critical infrastructure without acquiring a patch owner.