Attackers began actively exploiting CVE-2026-0768, an unauthenticated remote code execution flaw in the open-source Langflow AI application-building platform, to run arbitrary Python code with root privileges on unpatched servers. Security researchers detected roughly 360 exploitation attempts against honeypots, with attackers querying environment variables and configuration files to harvest Langflow admin keys, AWS secrets, and OpenAI API keys. The flaw affects Langflow versions 1.4.2 and earlier and is described as the platform’s twelfth actively exploited vulnerability disclosed in 2026.