# Langflow flaw is being exploited to harvest cloud and AI credentials

_Tuesday, September 1, 2026 at 1:54 PM EDT · Security, AI · Latest · Tier 1 — Major_

![Langflow flaw is being exploited to harvest cloud and AI credentials — Primary](https://www.bleepstatic.com/content/hl-images/2026/06/10/Langflow.jpg)

Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by BleepingComputer. The critical issue affects Langflow 1.4.2 and earlier and can execute arbitrary code with root privileges. VulnCheck observed 360 attacks as of September 1, including attempts to collect OpenAI API keys, AWS secrets and Langflow administrative credentials.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/)

---
Canonical: https://techandbusiness.org/newswire/WSxPILQuK89Yk3BZT_ZQDD
Retrieved: 2026-09-01T23:01:13.192Z
Publisher: Tech & Business (techandbusiness.org)
