VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_e0c03dad168c1e562526b2d6c1c9df19

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Published Jun 30, 2026

Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner.

The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI)

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.