# VulnCheck reports active exploitation of Langflow and Rails flaws

_Tuesday, September 1, 2026 at 3:22 AM EDT · Security · Latest · Tier 2 — Notable_

![VulnCheck reports active exploitation of Langflow and Rails flaws — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9_EygYWh8fZRphLL1V9dg-h1jgQ0f9xmlVuPwPAaaEUUCBkKbQ4nTaL27WIevCJg42GWtDGMKyRvzBUz9MWtD2FxPx7vCKwXLirO-N1YRcpPy0mX_B_fTG2gBS-JPRJGXfCh_I2yHJgoi1V5lve7Opcm-M0ApWs6gohPjNhBi-0CsP49guHlM2lzHLsiD/s1700-nu-rw-lo-l85-e365/lang.jpg)

Threat actors are exploiting critical vulnerabilities in Langflow and Ruby on Rails, according to VulnCheck. The reported Langflow flaw, CVE-2026-0768, can permit arbitrary Python execution as root, while the Rails issue CVE-2026-66066 can expose files, process secrets and credentials and lead to remote code execution under specified conditions. VulnCheck said it recorded more than 50 detections within hours on August 30, rising to 360 by Monday, with activity probing for cloud and OpenAI-related credentials.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html)

---
Canonical: https://techandbusiness.org/newswire/0raDZMSEKa1_giXaSl5xZQ
Retrieved: 2026-09-01T11:12:42.295Z
Publisher: Tech & Business (techandbusiness.org)
