Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical RCE in Langflow (CVE‑2026‑33017) and Trivy Supply‑Chain Compromise (CVE‑2026‑33634) Prompt Immediate Federal Action

CISA added two newly disclosed flaws to its catalog: a critical unauthenticated RCE in Langflow and a malicious‑code injection in Aqua Security’s Trivy scanner. Both are being weaponised in the wild, exposing credentials and threatening downstream supply‑chain integrity for organisations that rely on these open‑source tools.

LiveThreat™ Intelligence · 📅 March 27, 2026· 📰 helpnetsecurity.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
helpnetsecurity.com

Critical RCE in Langflow (CVE‑2026‑33017) & Trivy Supply‑Chain Compromise (CVE‑2026‑33634) Threaten AI Workflows and Container Scanning

What It Is – Two high‑severity vulnerabilities were added to CISA’s Known Exploited Vulnerabilities catalog. CVE‑2026‑33017 is a critical unauthenticated remote‑code‑execution flaw in Langflow 1.8.2 and earlier. CVE‑2026‑33634 is a malicious‑code injection in Aqua Security’s Trivy scanner that enables a supply‑chain compromise.

Exploitability – Langflow’s flaw was weaponised within 20 hours of advisory publication; attackers built exploits without a public PoC and began scanning the Internet. Trivy’s backdoor was observed in the wild on March 19 2026, attributed to the TeamPCP threat group. Both are actively exploited.

Affected Products – Langflow (open‑source AI‑agent framework, ≤ v1.8.2). Aqua Security Trivy (container image scanner, all versions containing the malicious payload).

TPRM Impact –

  • Credential theft from compromised Langflow instances can cascade to downstream databases and SaaS services.
  • Trivy’s supply‑chain breach can inject malicious code into any CI/CD pipeline that relies on its scanning results, affecting downstream applications and customers.

Recommended Actions –

  • Prioritise patching Langflow to ≥ v1.8.3 and apply the Trivy remediation released by Aqua Security.
  • Conduct immediate inventory of all third‑party services that consume Langflow APIs or Trivy scan results.
  • Deploy network segmentation and runtime detection to limit lateral movement from compromised instances.
  • Review and rotate any credentials or API keys exposed in logs or environment variables.
  • Update incident‑response playbooks to include rapid‑patch windows for zero‑day disclosures.

Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/03/27/cve-2026-33017-cve-2026-33634-exploited/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →