Threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails, leading to unauthorized remote code execution and the theft of sensitive cloud and database credentials.
Key Points
- CVE-2026-0768 allows unauthenticated attackers to execute arbitrary Python code as root within Langflow environments.
- CVE-2026-66066, dubbed KindaRails2Shell, enables file reading and credential theft in Ruby on Rails via malicious image uploads.
- VulnCheck recorded over 360 exploitation attempts targeting canary systems across the U.K., Singapore, and Israel since August 30, 2026.
- Attackers are harvesting environment variables, including AWS keys and OpenAI API tokens, to facilitate further system compromise.
- Security researchers warn that even patched Ruby on Rails servers may remain susceptible to remote code execution via deserialization gadgets.