IBM’s Langflow AI Platform Faces Active Exploitation Due to Critical Vulnerability

A serious vulnerability in IBM's Langflow AI platform allows unauthorized remote code execution, prompting urgent action for affected users.

A serious vulnerability in IBM's Langflow AI platform allows unauthorized remote code execution, prompting urgent action for affected users.

A public exploit has been released for a previously patched remote code execution vulnerability in vBulletin, affecting versions 6.2.1 and earlier, as well as 6.1.6 and earlier.

A newly identified exploit chain, named AutoJack, allows attackers to leverage an AI browsing agent for unauthorized code execution on local machines. This vulnerability affects specific pre-release versions of Microsoft's AutoGen Studio.

The ShinyHunters group has exploited a critical zero-day vulnerability in Oracle PeopleSoft, impacting numerous universities and potentially exposing sensitive data.

A serious security flaw in Hugging Face's LeRobot platform could allow unauthenticated attackers to execute arbitrary code remotely, raising significant security concerns.

A severe security flaw in SGLang, identified as CVE-2026-5760, poses significant risks of remote code execution through malicious model files.

Recent findings reveal two vulnerabilities in the CUPS printing system that could allow unauthenticated remote code execution and root access.

Microsoft's findings reveal a new method where threat actors utilize HTTP cookies to control PHP-based web shells, enabling remote code execution on Linux servers.

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical vulnerability affecting F5 BIG-IP APM to its Known Exploited Vulnerabilities catalog, following evidence of active exploitation.

A critical vulnerability in SolarWinds Web Help Desk is being actively exploited, prompting urgent patching requirements for U.S. federal agencies.