Path traversal flaw in AI dev platform Langflow exploited in attacks

2026-06-11T01:23:32Z49b28dfd6234cf5ef6bc7196a20e9d280f22988ecee012e47ac5adb26e4d94fa
CVE-2026-5027China-linkedGitHubIvanti SentryJDY botnetLangflowMiasmaMicrosoft DefenderMicrosoft ExchangeOracle PeopleSoftRoguePlanetServiceNow incident','unauthenticated API'ShinyHuntersXSSactive exploitationarbitrary file writecredential stealerdata theftmilitary targetingnpmpath traversalremote code executionroot privilegesupply chainzero-day

What happened

Multiple active security incidents and high-impact vulnerability disclosures: attackers are actively exploiting a high-severity path traversal in Langflow (CVE-2026-5027) to write arbitrary files on exposed AI-dev servers. Other notable events include the brief public leak of the Miasma credential‑stealer source, GitHub/npm mitigations for supply‑chain attacks, ShinyHunters data thefts targeting Oracle PeopleSoft, expansion of the China-linked JDY botnet with U.S. military targeting, and a ServiceNow incident exposing customer data via an unauthenticated API. Microsoft patched an Exchange XSS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
49b28dfd6234cf5ef6bc7196a20e9d280f22988ecee012e47ac5adb26e4d94fa
Enrichment time
2026-06-11T01:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.