// OpenaiHIGH
Threat actors are actively exploiting a critical remote code execution vulnerability (CVE-2026-0768) in Langflow, a low-code AI application platform, to harvest OpenAI API credentials along with AWS keys. VulnCheck detected over 50 exploitation attempts originating from Russia targeting exposed Langflow instances, with attackers querying environment variables for OPENAI_API keys and other sensitive cloud credentials. Organizations using Langflow should immediately patch, rotate exposed OpenAI and AWS credentials, and restrict public access to Langflow deployments.
- Hackers Exploit Langflow RCE Flaw to Harvest OpenAI and AWS Cred(opens in a new tab)
- Critical Langflow flaw exploited to steal OpenAI and AWS keys(opens in a new tab)
- Critical Langflow Flaw Exploited as Attacks on AI Platform Rise(opens in a new tab)
// Get alerts for Openai