Exploited in the wild Langflow ai-ml N-central IBM rce
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
CVE Tools coverage
Federal agencies have until July 7 to address three actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, as highlighted by CISA. The most severe flaw, CVE-2026-9198 in IBM's Langflow, enables unauthenticated remote code execution with a CVSS score of 9.8. A related vulnerability, CVE-2026-0770, also allows RCE with root privileges and has already seen public PoCs. Meanwhile, a patched but re-exploitable flaw in N-central (CVE-2026-18576) permits unauthorized account takeover, while Apache Tomcat faces an incomplete fix for another issue (CVE-2026-34486). All three vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities list.