A severe vulnerability known as CVE-2026-33017, which impacts the Langflow framework for creating AI agents, is being actively exploited by hackers, according to a warning from the Cybersecurity and Infrastructure Security Agency (CISA).
Threat actors can create public flows without authentication by using the security flaw, which has a critical score of 9.3 out of 10.
The government classified the problem as a code injection vulnerability and added it to the list of known exploited vulnerabilities.
Hackers began attacking CVE-2026-33017 on March 19, almost 20 hours after the vulnerability warning became public, according to researchers at application security firm Sysdig.
At the time, there was no public proof-of-concept (PoC) exploit code read more about CISA New Langflow flaw actively exploited to hijack AI workflows.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
