VMTech
Discuss a project

VulnCheck Detects Active Exploitation of Langflow and Rails Flaws

VulnCheck Detects Active Exploitation of Langflow and Rails Flaws

VulnCheck has detected active exploitation of two critical vulnerabilities affecting Langflow and Ruby on Rails: CVE-2026-0768, with a CVSS score of 9.8, and CVE-2026-66066, also known as KindaRails2Shell, with a score of 9.5. The company recorded more than 50 detections within hours on August 30, 2026; that total had risen to 360 by Monday.

CVE-2026-0768 is an input-validation flaw in Langflow that can allow arbitrary Python code execution in the context of the root user. CVE-2026-66066 can enable an unauthenticated attacker to read arbitrary server files, expose Rails process environment data and secrets, and ultimately achieve remote code execution.

Credential probing targets AI platform environments

VulnCheck said adversaries exploiting Langflow appear to be combining reconnaissance with credential harvesting. Observed requests queried environment variables including LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS* and AWS_SECRET*. They also attempted to read /root/.cache/langflow/secret_key and checked SSH access and the size of .bash_history.

The observed traffic primarily originated from Russia and had, at that point, exclusively hit VulnCheck canaries in the United Kingdom. Most vulnerable Langflow hosts were located in the United States, Germany, Malaysia, Brazil and India.

VulnCheck has also observed attackers exploiting as many as 12 vulnerabilities since 2025. More than 15,000 successful attempts involved CVE-2026-0769, CVE-2025-3248 and CVE-2026-5027. In one canary incident, attackers used CVE-2026-5027 to deploy a Python credential harvester, proxy agents and SimpleHelp remote-access software.

Rails image processing creates an exposure path

KindaRails2Shell can be exploited through a crafted image upload because Active Storage and libvips handle input files differently. Successful exploitation requires an affected application to use libvips for Active Storage image processing and accept image uploads from untrusted users.

VulnCheck detected active exploitation of CVE-2026-66066 against canaries in Singapore, Israel and the United Kingdom. Researcher Patrick Garrity said the activity originated from one IP address in France and established command-and-control with a host in Israel. As of early August, VulnCheck had identified more than 7,100 exposed vulnerable Ruby on Rails instances.

Patch validation remains necessary

VulnCheck tested a patched Rails 8.1.3.1 server and found that the fix blocked the libvips file read but did not neutralize variation-key Marshal deserialization. The company said an RCE gadget could still execute on a patched server when given a valid signature.

For businesses, the immediate implication is to treat Langflow deployments and Rails applications processing untrusted image uploads as potential routes to cloud credentials and connected systems. Teams should identify exposed instances, validate the behavior of deployed fixes, review upload handling and rotate secrets that may have been accessible to an attacker.

#cybersecurity#vulnerability#rails#langflow
Open analytics
On the site 0 views
min read 3 01.09.2026
Instagram

VulnCheck Detects Active Exploitation of Langflow and Rails Flaws

Open the post on Instagram ↗