As cited
Copy frozen at (site build).
vulnerabilities
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero miners on exposed AI application endpoints. The attacks target CVE-2024-33017, which has a CVSS score of 9.3, and indicate broad scanning for vulnerable instances. The activity demonstrates continued weaponization of the Langflow flaw for cryptocurrency mining purposes.
Why it matters: Organizations running exposed Langflow instances need to patch immediately, as unauthenticated RCE with a 9.3 CVSS score is actively exploited for initial compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Attackers are exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow with a CVSS score of 9.3, to deploy Monero cryptocurrency miners. The campaign targets exposed artificial intelligence application endpoints through active scanning and exploitation.
Why it matters: Organizations running exposed Langflow instances are at immediate risk of remote code execution and cryptojacking; patch or isolate affected systems now.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Attackers are exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow with a CVSS score of 9.3, to deploy Monero cryptocurrency miners. The campaign targets exposed artificial intelligence application endpoints through active scanning and exploitation.
Why it matters: Organizations running exposed Langflow instances are at immediate risk of remote code execution and cryptojacking; patch or isolate affected systems now.
- Source published
- First seen by Cybersecurity Tracker