> Critical Langflow flaw exploited to steal OpenAI and AWS keys
[AUTHOR: Bill Toulas]
[DATE: 01/09/2026 17:54]
[LANGUAGE: EN]
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]