Threat actors are actively exploiting two critical remote code execution vulnerabilities affecting Langflow and Ruby on Rails.
The campaigns target internet-exposed installations of the low-code AI application platform and the widely deployed web framework, underscoring how rapidly attackers are operationalizing newly disclosed flaws.
The first issue, CVE-2026-0768, is an unauthenticated remote code execution vulnerability in Langflow’s custom-component editor.
Critical Langflow and Ruby on Rails Flaws
The flaw lies in the code-validation path, where insufficient validation of a user-supplied parameter before it is used to execute Python can allow an attacker to run code in the context of the root user.
Caitlin Condon said its Canaries began recording first-time exploitation only hours earlier, despite no known public proof-of-concept exploit for the vulnerability.
Researchers recorded more than 50 detections during the morning of the activity. The observed requests combined discovery and credential-harvesting behavior.
Payloads queried environment variables potentially holding privileged Langflow, OpenAI API, and AWS access-key material; attempted to read Langflow’s cached secret key; and checked SSH accessibility and the size of Bash history files.
Traffic predominantly originated in Russia and, at the time of reporting, had exclusively reached Canary systems in the United Kingdom.
CVE-2026-0768 was disclosed through Trend Micro’s Zero Day Initiative in January and was added to VulnCheck’s Known Exploited Vulnerabilities catalog on August 29. It carries a CVSS score of 9.8.
The addition is significant because VulnCheck has listed several other Langflow vulnerabilities as exploited this year, suggesting sustained adversary attention on exposed AI-workflow infrastructure.
Separately, VulnCheck observed active exploitation of CVE-2026-66066, a critical Ruby on Rails vulnerability described as an Active Storage file-read-to-RCE issue.
Affected Rails versions permit a crafted upload to invoke an operation after Active Storage fails to disable “blobs” operations marked unsafe for untrusted content.
The condition may expose files accessible to the Rails process, including environment variables and application secrets, thereby enabling remote code execution or lateral movement.
The Rails activity hit Canary deployments in Singapore, Israel, and the United Kingdom. VulnCheck traced the campaign to a single French IP address and reported that the intruder established command-and-control communications with a host in Israel.
CVE-2026-66066 has a CVSS score of 9.5 and affects Rails versions before 7.2.3.2, 8.0.5.1, and 8.1.3.1; fixes are available in those releases.
Organizations should urgently identify externally reachable Langflow and Rails assets, apply vendor updates, rotate potentially exposed credentials, and inspect logs for suspicious environment-variable queries, secret-key reads, and unusual uploads.
Defenders should also deploy available network and endpoint detection content, restrict access to administrative interfaces, and treat evidence of exploitation as a possible root-level compromise that requires a full incident response. Immediate containment is essential because both vulnerabilities offer attackers a direct foothold.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN