Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE
A high-severity path traversal vulnerability in Langflow, designated CVE-2026-5027 (CVSS 8.8), is being actively exploited in the wild. Discovered by Tenable, the…
A high-severity path traversal vulnerability in Langflow, designated CVE-2026-5027 (CVSS 8.8), is being actively exploited in the wild. Discovered by Tenable, the…
Langflow is an open-source AI application development platform that has been targeted by multiple RCE vulnerabilities.
OpenClaw, formerly Clawdbot and Moltbot, is an open-source autonomous assistant used in mind virus experiments. Its default soul file was exploited in…
PostgreSQL is used by Splunk Enterprise as a sidecar service. The vulnerability CVE-2026-20253 exploits the PostgreSQL sidecar endpoint to achieve unauthenticated file…
Mastra is an open-source JavaScript and TypeScript framework for building AI applications. In June 2026, 145 of its npm packages were compromised…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
PostgreSQL is an advanced open-source relational database. 16% of organizations expose Postgres to the internet, making it a common attack vector.
RustDesk is an open-source remote desktop software used by Armored Likho to capture victim credentials.
RustDesk is an open-source remote desktop software that Armored Likho installs on compromised machines. The stealer prompts victims to enter credentials, then…
NGINX Open Source versions 1.31.0-1.31.1 are vulnerable to two critical remote code execution flaws; fixed in 1.31.2.