A cryptocurrency-mining campaign is actively exploiting CVE-2026-33017, an unauthenticated RCE vulnerability in Langflow, to deploy the lambsys malware. The attack chain involves a bash dropper that establishes SSH-based lateral movement, followed by a Go-based payload that systematically disables Linux security controls, eliminates rival miners, and deploys a customized XMRig miner.
CVE-2026-33017
2 posts
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-33017, a code injection vulnerability affecting Langflow, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce their exposure to cyberattacks.