Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
2026-07-08T14:51:52Z•fb9b3a246916ba349d7d13b5ccfd73102fbb8eabc347b8e28fcdf763555b4d43
AI securityAccentureAzure tokensCISACVE-2026-55255ITDRKnown Exploited VulnerabilitiesLangflowRSA keysSSH keysactive exploitationcredential harvestingdata breachproduct announcementssource code theftsupply-chain risk
What happened
This feed highlights active exploitation and high-risk incidents plus several vendor product updates. Key security items: 1) CISA added Langflow vulnerability CVE-2026-55255 to its Known Exploited Vulnerabilities catalog after Sysdig observed active targeting — attackers are leveraging the Langflow flaw for credential harvesting. Langflow is an open-source visual framework used for building AI agents and workflows. 2) Accenture acknowledged a security incident after a threat actor claimed to exfiltrate ~35 GB of source code and sensitive artifacts (RSA/SSH keys, Azure personal access tokens, A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- fb9b3a246916ba349d7d13b5ccfd73102fbb8eabc347b8e28fcdf763555b4d43
- Enrichment time
- 2026-07-08T14:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.