Attackers Actively Exploiting Critical Vulnerabilities in Langflow and Ruby on Rails
Threat actors are actively exploiting two critical vulnerabilities: CVE-2026-0768 in Langflow, allowing arbitrary Python code execution, and CVE-2026-66066 (KindaRails2Shell) in Ruby on Rails, which can lead to arbitrary file reading, leakage of environment secrets, and remote code execution. VulnCheck reported over 360 detections of these exploits as of Monday, indicating widespread credential-probing and command-and-control activity.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai