Path traversal flaw in AI dev platform Langflow exploited in attacks
2026-06-11T01:23:32Z•49b28dfd6234cf5ef6bc7196a20e9d280f22988ecee012e47ac5adb26e4d94fa
CVE-2026-5027China-linkedGitHubIvanti SentryJDY botnetLangflowMiasmaMicrosoft DefenderMicrosoft ExchangeOracle PeopleSoftRoguePlanetServiceNow incident','unauthenticated API'ShinyHuntersXSSactive exploitationarbitrary file writecredential stealerdata theftmilitary targetingnpmpath traversalremote code executionroot privilegesupply chainzero-day
What happened
Multiple active security incidents and high-impact vulnerability disclosures: attackers are actively exploiting a high-severity path traversal in Langflow (CVE-2026-5027) to write arbitrary files on exposed AI-dev servers. Other notable events include the brief public leak of the Miasma credential‑stealer source, GitHub/npm mitigations for supply‑chain attacks, ShinyHunters data thefts targeting Oracle PeopleSoft, expansion of the China-linked JDY botnet with U.S. military targeting, and a ServiceNow incident exposing customer data via an unauthenticated API. Microsoft patched an Exchange XSS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 49b28dfd6234cf5ef6bc7196a20e9d280f22988ecee012e47ac5adb26e4d94fa
- Enrichment time
- 2026-06-11T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.