Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity Ravie LakshmananSep 01, 2026Vulnerability / Artificial Intelligence Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below – CVE-2026-0768 (CVSS score: 9.8) – A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka KindaRails2Shell (CVSS score: 9.5) – A vulnerability that could allow an unauthenticated attacker to read arbitrary files from the server, leak Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens,…
CVEs: CVE-2026-0768, CVE-2026-66066, CVE-2026-0769, CVE-2025-3248, CVE-2026-5027
Original source: thehackernews.com