VMTech
Discuss a project

CISA adds exploited Langflow, Tomcat and N-central flaws to KEV catalog

CISA adds exploited Langflow, Tomcat and N-central flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency added three vulnerabilities affecting Langflow, Apache Tomcat and N-able N-central to its Known Exploited Vulnerabilities catalog on August 5, 2026, citing evidence of active exploitation. The entries include a critical Langflow remote-code-execution flaw rated 9.8, a Tomcat cluster-encryption weakness rated 7.5 and an N-central authentication bypass rated 8.2.

Federal Civilian Executive Branch agencies must apply the necessary fixes by August 7, 2026. The short deadline reflects the presence of active threats rather than theoretical exposure.

Langflow and N-central require close patch checks

CVE-2026-9198 is a code-injection vulnerability that lets unauthenticated attackers obtain full remote code execution on default Langflow deployments. Langflow fixed it in July 2026 with version 1.10.1. No details are currently available about how attackers are exploiting this specific flaw.

Security defects in the open-source AI application development platform have nevertheless been weaponized repeatedly in recent months. The broader pattern described in AI-agent vulnerabilities and rising security incidents provides useful context for the growing role of AI agents in security incidents without changing the immediate priority: exposed Langflow systems should be upgraded.

CVE-2026-18556 affects N-able N-central and allows authentication bypass. An incomplete initial fix led N-able to issue another patch tracked as CVE-2026-18577, also rated 8.2. The latter had already entered the KEV catalog on Monday; the new addition indicates that threat actors are exploiting both vulnerabilities.

Tomcat exploitation linked to an AI-enabled campaign

CVE-2026-34486 stems from missing encryption of sensitive data in Apache Tomcat. It enables a bypass of EncryptInterceptor, the cluster component that adds pre-shared-key encryption to messages exchanged between nodes. Apache fixed the issue in April 2026 through Tomcat 11.0.21, 10.1.54 and 9.0.117.

Palo Alto Networks Unit 42 attributed exploitation of the Tomcat flaw to an AI-enabled autonomous hacking campaign run by a Chinese-speaking actor using the aliases knaithe and KnYuan. The actor, based in Zhuhai, China, used DeepSeek through the Hermes Agent framework as an offensive operator against internet-exposed devices.

When attempts to exploit Langflow flaw CVE-2026-33017 failed because of restrictive target configurations, the AI agent autonomously researched other higher-value weaknesses, including flaws in n8n. Unit 42 also observed the adversary conducting manual operations against known vulnerabilities in Citrix NetScaler, Marimo, Apache Tomcat and IKE VPN endpoints.

Unit 42 said the actor attempted to exploit more than 460 targets using autonomous and manual techniques. DeepSeek appeared to narrow the targeting scope to conserve AI compute, completing hundreds of hours of manual targeting analysis in minutes while managing its own resources.

What businesses should do now

Security teams should inventory internet-facing Langflow, Tomcat and N-central deployments, compare them with the fixed versions, and prioritize remediation where exposure exists. They should also verify that N-central received the follow-up repair rather than relying on the incomplete fix, then review affected systems for evidence of compromise. The campaign demonstrates why patch decisions must account for both confirmed exploitation and the speed at which automated tooling can evaluate potential targets.

#cybersecurity#vulnerabilities#patchmanagement#aisecurity
Open analytics
On the site 1 views
min read 4 05.08.2026
Instagram

CISA adds exploited Langflow, Tomcat and N-central flaws to KEV catalog

Open the post on Instagram ↗