Multiple outlets report that attackers are actively exploiting CVE-2026-5027, a high-severity vulnerability in Langflow, an open-source low-code platform used to build AI applications. The flaw is disclosed in March and is described as a path traversal issue. According to reporting from VulnCheck referenced by The Hacker News, the vulnerability has a CVSS score of 8.8 and enables unauthenticated attackers to manipulate server paths to write files to arbitrary locations on affected systems.

SecurityWeek and Bleeping Computer both describe the exploitation as remote and ongoing, targeting exposed Langflow installations. The reported outcome is that adversaries can create or overwrite files on the server outside intended directories by abusing the affected request handling, with the impact extending to potential remote code execution depending on how the written files are used. No sources provide details about specific attacker groups or the final payloads. The common theme across the articles is that the flaw remains unpatched in reported cases and is being used to gain unauthorized capabilities through direct file write access.