Critical Flaws in Langflow and Ruby on Rails Under Active Attack
Security researchers at VulnCheck have found that hackers are actively exploiting two critical vulnerabilities: one in Langflow, a popular tool for building AI workflows, and another in Ruby on Rails, a widely used web application framework. The Langflow flaw, CVE-2026-0768, carries a near-maximum severity score of 9.8 out of 10 and stems from a failure to properly validate user input. If exploited, it allows attackers to run arbitrary Python code with root-level privileges on affected systems - effectively giving them full control.
The Rails vulnerability, tracked as CVE-2026-66066, is also being actively targeted, according to the research. Attackers are using these flaws for credential-probing activity and to establish command-and-control (C2) connections, meaning compromised systems can be remotely controlled and used as a foothold for further attacks, data theft, or spreading malware across a network.
Both Langflow and Ruby on Rails are commonly used in web applications and AI-related development environments, making organisations that rely on these technologies - including many small businesses using third-party developers or AI tools - potential targets. Because exploitation is already occurring in the wild, patching quickly is critical rather than optional.