Critical Langflow and Ruby on Rails Vulnerabilities Exploited for Credential Harvesting and C2 Activities
Attackers are exploiting critical vulnerabilities in Langflow and Ruby on Rails (CVE-2026-0768 and CVE-2026-66066) to conduct credential probing and command-and-control (C2) activities, with traffic originating from Russia targeting systems in the UK and other regions. The flaws enable arbitrary code execution and sensitive data leakage, affecting AI development platforms and cloud environments.
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.
The vulnerabilities in question are listed below -
CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka
*** END OF TRANSMISSION ***