Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unveiling the Critical Flaws: Langflow and Ruby on Rails Vulnerabilities Exposed


Threat actors have exploited critical vulnerabilities in Langflow and Ruby on Rails, compromising the security of numerous applications and systems. Learn more about the vulnerabilities and the implications for the cybersecurity landscape in this in-depth article.

  • Threat actors have exploited critical vulnerabilities in Langflow and Ruby on Rails, compromising numerous applications and systems.
  • Two severe flaws have been identified, CVE-2026-0768 and CVE-2026-66066, with CVSS scores of 9.8 and 9.5, respectively.
  • CVE-2026-0768 allows an attacker to execute arbitrary Python code in the context of the root user, while CVE-2026-66066 enables arbitrary file reading, leak of Rails process environment and secrets, and remote code execution.
  • Over 360 detections of CVE-2026-66066 have been recorded within a few hours of August 30, 2026, with most attacks originating from Russia and targeting Canaries in the UK.
  • The exploitation of these vulnerabilities has resulted in the compromise of numerous systems and applications, including Langflow hosts in the U.S., Germany, Malaysia, Brazil, and India.
  • Threat actors have exploited as many as 12 vulnerabilities since 2025, with over 15,000 successful attempts leveraging specific vulnerabilities.
  • Organizations must prioritize the remediation of these flaws, implement robust security measures, and invest in threat intelligence to stay ahead of the evolving threat landscape.



  • Threat actors have recently exploited critical vulnerabilities in Langflow and Ruby on Rails, compromising the security of numerous applications and systems. According to recent findings from VulnCheck, two severe flaws have been identified,CVE-2026-0768 and CVE-2026-66066, which have been found to be exploited by attackers.

    CVE-2026-0768, a lack of proper validation of a user-supplied input vulnerability, allows an attacker to execute arbitrary Python code in the context of the root user. This vulnerability has a CVSS score of 9.8, indicating a high level of severity. The vulnerability can be exploited by an attacker to gain elevated privileges on the system.

    CVE-2026-66066, also known as KindaRails2Shell, is a vulnerability that allows an unauthenticated attacker to read arbitrary files from the server, leak Rails process environment and secrets, and ultimately lead to remote code execution. This vulnerability has a CVSS score of 9.5, indicating a high level of severity. The vulnerability can be exploited by an attacker by uploading a crafted image, taking advantage of the discrepancy between Active Storage and libvips in how they read input files.

    VulnCheck has recorded over 360 detections of CVE-2026-66066 within a few hours of August 30, 2026, and the figure has since risen to 50 detections. The attack primarily originates from Russia and has exclusively hit Canaries in the U.K. The exploitation of this vulnerability has been observed in one case against the canary systems, where unknown threat actors have been observed exploiting CVE-2026-5027 to drop a Python credential harvester, proxy agents, and SimpleHelp for remote access.

    The findings highlight increased threat actor interest in AI development platforms, which can provide access to sensitive credentials, cloud environments, and other connected systems. The exploitation of these vulnerabilities has resulted in the compromise of numerous systems and applications, including vulnerable Langflow hosts located in the U.S., Germany, Malaysia, Brazil, and India.

    Threat actors have exploited as many as 12 vulnerabilities since 2025, with more than 15,000 successful attempts leveraging CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027. The majority of the vulnerable Langflow hosts are located in the U.S., Germany, Malaysia, Brazil, and India.

    The exploitation of these vulnerabilities has significant implications for the security of AI development platforms and the broader cybersecurity landscape. As threat actors continue to exploit these vulnerabilities, it is essential for organizations to prioritize the remediation of these flaws and implement robust security measures to protect against future attacks.

    In response to the growing threat of AI-powered attacks, experts are emphasizing the need for threat intelligence and vulnerability management. Organizations must prioritize the development of robust security protocols and invest in threat intelligence to stay ahead of the evolving threat landscape.

    Threat actors are increasingly using AI-powered attacks to exploit vulnerabilities and compromise systems. The exploitation of CVE-2026-66066 highlights the need for organizations to prioritize the remediation of these vulnerabilities and implement robust security measures to protect against future attacks.

    The recent findings from VulnCheck demonstrate the critical importance of vulnerability management and threat intelligence in the face of evolving threats. As the threat landscape continues to evolve, it is essential for organizations to prioritize the development of robust security protocols and invest in threat intelligence to stay ahead of the threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unveiling-the-Critical-Flaws-Langflow-and-Ruby-on-Rails-Vulnerabilities-Exposed-ehn.shtml

  • https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html

  • https://undercodenews.com/critical-langflow-and-ruby-on-rails-exploits-trigger-a-new-wave-of-attacks-as-threat-actors-hunt-for-ai-credentials-and-server-secrets-video/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-0768

  • https://www.cvedetails.com/cve/CVE-2026-0768/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-66066

  • https://www.cvedetails.com/cve/CVE-2026-66066/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-0769

  • https://www.cvedetails.com/cve/CVE-2026-0769/

  • https://nvd.nist.gov/vuln/detail/CVE-2025-3248

  • https://www.cvedetails.com/cve/CVE-2025-3248/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-5027

  • https://www.cvedetails.com/cve/CVE-2026-5027/


  • Published: Tue Sep 1 03:09:44 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us