Loading...
Loading...
A critical unauthenticated flaw (CVE-2026-33017) let anyone run code on internet-exposed Langflow servers with a single request — and attackers used it to plant a Monero miner and an SSH-key-reuse worm within ~20 hours of disclosure.