F5 Labs published honeynet data on 6 October showing opportunistic scanning of CVE-2026-0768, an unauthenticated code-injection flaw in the Langflow AI application builder. Every one of 405 requests in September hit POST /api/v1/validate/code. The Zero Day Initiative rates it 9.8. The vulnerable handler evaluates attacker-supplied Python before authentication. If the service runs as root, that is root.
What happened
The bug was disclosed in January 2026 as ZDI-26-034. Exploitation did not stay theoretical. VulnCheck reported attempts from 29 August. F5's September sensors saw 55 source addresses, with bursts rather than a steady drip. The largest day was 26 September, about 40 percent of the month.
The payloads are not just probes. One cluster raises an exception carrying a unique marker, then uses a sleep to confirm execution. Another dumps the process environment with env, falling back to /proc/self/environ, which is where cloud keys and model API tokens usually sit. A third runs id through a default-argument trick. Some requests spoof localhost in forwarding headers. Others rotate User-Agent strings that look like AI crawlers.
Who is affected
- Self-hosted Langflow reachable from the internet, especially builds up to and including 1.4.2, which ZDI lists as affected.
- Any instance where /api/v1/validate/code answers without authentication in front of it.
- Deployments that keep cloud credentials, model keys, or SSH material in the process environment.
What to do now
Take internet-facing Langflow off the public network, upgrade to a current release, and rotate every secret that process could read. A patch does not expire a key that was already dumped.
Search access logs for POST /api/v1/validate/code from outside the team, and for request bodies that call exec, env, or /proc/self/environ. If those lines exist, assume the cloud and AI keys on that host are burned. Langflow is a developer tool. It is now on the same scan list as mail servers and VPNs.
Source: F5 Labs, published 6 October 2026. https://www.f5.com/labs/articles/attackers-target-ai-development-platform-langflow
Also on the blog
- FortiMail CVE-2026-104286 (CVSS 9.8) file-write zero-day
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Atlassian CVE-2026-21589: unauthenticated file access, CVSS 9.3
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.