[KEV] CVE-2026-0770 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-0770 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-0770 is a remote code execution vulnerability in Langflow, the open-source AI workflow builder, caused by inclusion of functionality from an untrusted control sphere that allows unauthenticated remote attackers to execute arbitrary code on affected installations.
Technical Detail
The flaw stems from Langflow's handling of externally supplied components or code references without adequate trust boundary enforcement, permitting an attacker to introduce and execute arbitrary logic within the application's runtime context. A remote attacker can exploit this without requiring local access by supplying crafted input that causes the application to load and execute code from an untrusted source. Successful exploitation results in full remote code execution under the privileges of the Langflow process, which in many deployment configurations runs with broad system or container-level access.
Exploitation Status
CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities catalog on July 21, 2026. The exploit maturity is rated Operational, meaning functional exploit code capable of reliable, real-world use exists and has been observed being used against live targets. This is not a theoretical or proof-of-concept risk.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established in available intelligence. Given the active exploitation status and the nature of the target, opportunistic actors scanning for exposed Langflow instances should be assumed.
What To Do
Per CISA's Known Exploited Vulnerabilities binding directive, federal agencies and organizations subject to BOD 22-01 must apply vendor-supplied patches or implement mitigations by the deadline associated with the July 21, 2026 KEV listing. Organizations should immediately identify all internet-exposed Langflow deployments and apply the latest available patch from the Langflow project. If patching cannot be completed immediately, restrict network access to Langflow instances to trusted IP ranges only and disable any features that allow loading of external components or custom code. Monitor application logs for unexpected outbound connections, unusual process spawning, or anomalous component loading activity as indicators of exploitation. Treat any unpatched, externally accessible Langflow instance as actively at risk given confirmed in-the-wild exploitation.