CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 59

As cited

Copy frozen at (site build).

vulnerabilities

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero miners on exposed AI application endpoints. The attacks target CVE-2024-33017, which has a CVSS score of 9.3, and indicate broad scanning for vulnerable instances. The activity demonstrates continued weaponization of the Langflow flaw for cryptocurrency mining purposes.

Why it matters: Organizations running exposed Langflow instances need to patch immediately, as unauthenticated RCE with a 9.3 CVSS score is actively exploited for initial compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Attackers are exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow with a CVSS score of 9.3, to deploy Monero cryptocurrency miners. The campaign targets exposed artificial intelligence application endpoints through active scanning and exploitation.

Why it matters: Organizations running exposed Langflow instances are at immediate risk of remote code execution and cryptojacking; patch or isolate affected systems now.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Attackers are exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow with a CVSS score of 9.3, to deploy Monero cryptocurrency miners. The campaign targets exposed artificial intelligence application endpoints through active scanning and exploitation.

Why it matters: Organizations running exposed Langflow instances are at immediate risk of remote code execution and cryptojacking; patch or isolate affected systems now.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary