CISA: New Langflow flaw actively exploited to hijack AI workflows
A severe vulnerability known as CVE-2026-33017, which impacts the Langflow framework for creating AI agents, is being actively exploited by hackers, according to a warning from the Cybersecurity and Infrastructure Security Agency (CISA).
Threat actors can create public flows without authentication by using the security flaw, which has a critical score of 9.3 out of 10.
The government classified the problem as a code injection vulnerability and added it to the list of known exploited vulnerabilities.
Hackers began attacking CVE-2026-33017 on March 19, almost 20 hours after the vulnerability warning became public, according to researchers at application security firm Sysdig.
At the time, there was no public proof-of-concept (PoC) exploit code read more about CISA New Langflow fl...

