CVE-2026-0770 Exploited in the Wild: Langflow RCE Added to CISA KEV
KEVIntel first observed remote code execution attempts against Langflow’s code-validation endpoint on 27 June 2026, 24 days before CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog.
Between 27 June and 21 July, KEVIntel sensors retained 137 exploitation attempts from 46 unique source IP addresses. The