CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These include a critical remote code execution (RCE) flaw in Langflow (CVE-2026-9198, CVSS 9.8), an encryption bypass in Apache Tomcat (CVE-2026-34486, CVSS 7.5), and an authentication bypass in N-able N-central (CVE-2026-18556, CVSS 8.2). Attackers are exploiting these flaws, with some linked to a Chinese-speaking threat actor using AI-powered tools like Hermes Agent and DeepSeek to automate attacks. Federal agencies have until August 7, 2026, to apply available patches.