SECURITY·중요도 9·2026. 09. 01.·The Hacker News

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

── KO ──────────────────

Langflow와 Ruby on Rails의 심각한 취약점이 악용되고 있다.

VulnCheck의 새로운 발견에 따르면, Langflow와 Ruby on Rails에 영향을 미치는 두 가지 심각한 취약점이 악용되고 있다. 첫 번째 취약점(CVE-2026-0768)은 사용자 입력의 적절한 검증 부족으로 인해 루트 사용자 컨텍스트에서 임의의 파이썬 코드를 실행할 수 있게 한다. CVSS 점수는 9.8로 높은 위험성을 지니고 있다.


── EN ──────────────────

Critical vulnerabilities in Langflow and Ruby on Rails are being exploited by attackers.

According to new findings from VulnCheck, attackers are exploiting two critical vulnerabilities impacting Langflow and Ruby on Rails. The first vulnerability (CVE-2026-0768) involves a lack of proper validation of user-supplied input that could allow arbitrary Python code execution within the context of the root user. It has a high CVSS score of 9.8, indicating significant risk.

원문 보기 →목록으로