▸ AI/LLM · Sysdig
Critical Langflow Vulnerability Exploited Within 20 Hours of Disclosure
A critical remote code execution vulnerability (CVE-2026-33017) in the popular AI workflow platform Langflow was weaponized by attackers just 20 hours after the March 17 advisory was published. No public proof-of-concept existed; attackers built working exploits directly from the advisory description and began harvesting API keys for OpenAI, Anthropic, and AWS from compromised instances. CISA has added it to the Known Exploited Vulnerabilities catalog.
The bottom line: Marketing data teams using Langflow or similar AI orchestration tools must immediately audit their deployments and rotate all connected credentials and API keys.