The Hacker News · 9/1/2026

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

CVE-2026-0768 (CVSS 9.8): Langflow input validation flaw allows arbitrary Python code execution as root; CVE-2026-66066 in Rails also actively exploited.

Read original coverage