CVE
CVE-2026-5027
- First Reported
- Sep 30, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (1)
- CVE-2026-5027 (Langflow): Path traversal file write in the POST /api/v2/files upload handler, allowing remote threat actors to drop unauthorized files (e.g., cron jobs, Secure Shell (SSH) keys) onto the host. Google Finds AI Is Changing Vulnerability Discovery and Exploitation Trends
CVE (3)
Malware (2)
MITRE ATT&CK (1)
Vendors (5)
Products (12)
Tools (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.