top of page
perceptive_background_267k.jpg

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

Published:

5 August 2026 at 15:51:33

Alert date:

5 August 2026 at 16:01:14

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities, Identity & Access, Emerging Technologies

CISA has issued an urgent warning to federal agencies, mandating mitigation of critical vulnerabilities in three products within three days. The affected products are IBM Langflow, N-central (network management software), and Apache Tomcat. All three vulnerabilities are confirmed as actively exploited in the wild. CISA added these flaws to its Known Exploited Vulnerabilities (KEV) catalog, triggering the mandatory remediation directive for federal civilian agencies under BOD 22-01. The urgency of the three-day deadline underscores the severity and active exploitation status of these vulnerabilities. Organizations using these products are strongly advised to apply patches or mitigations immediately. Apache Tomcat is widely deployed across enterprise environments, making it a particularly high-impact target. The inclusion of AI-related tooling like Langflow highlights growing attacker interest in AI infrastructure components.

Technical details

Three actively exploited vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog: (1) CVE-2026-9198 in IBM Langflow (CVSS 9.8 critical) - allows unauthenticated remote code execution on default Langflow deployments by chaining two API endpoints to bypass login and execute code; multiple public proof-of-concept exploits exist. A related Langflow flaw CVE-2026-0770 was previously flagged for RCE with root privileges. (2) CVE-2026-18576 in N-able N-central - a high-severity authentication bypass allowing attackers to hijack administrative accounts without credentials; an initial patch was insufficient, and threat actors found a new exploitation path. An emergency hotfix was released on a Sunday. (3) CVE-2026-34486 in Apache Tomcat (CVSS 7.5 high) - stems from an incomplete fix for CVE-2026-29146 (CVSS 9.8, missing encryption of sensitive data); a Chinese-speaking threat actor attempted to exploit this in a manual campaign to plant reverse shells on nine Apache Tomcat servers, as reported by Palo Alto Networks Unit 42 on July 30. CISA has not confirmed whether any of these vulnerabilities are being used in ransomware campaigns.

Mitigation steps:

1. Federal agencies have been ordered by CISA to apply available mitigations for all three affected products by end of Friday, July 7th. 2. For IBM Langflow (CVE-2026-9198 and CVE-2026-0770): Apply vendor patches immediately; restrict access to Langflow API endpoints; avoid default deployments exposed to the internet. 3. For N-able N-central (CVE-2026-18576): Install the emergency hotfix released by N-able as soon as possible; all versions before 2026.3 are impacted; monitor for unauthorized administrative account access. 4. For Apache Tomcat (CVE-2026-34486): Apply the latest patch addressing the incomplete fix for CVE-2026-29146; monitor servers for signs of reverse shell activity or unauthorized connections. 5. Check CISA's KEV catalog for the latest guidance: https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog. 6. Investigate whether any of these vulnerabilities are being leveraged as part of broader ransomware or multi-stage attack campaigns in your environment.

Affected products:

IBM Langflow (visual framework for building AI agents) - default deployments affected by CVE-2026-9198
Langflow - affected by CVE-2026-0770
N-able N-central (remote monitoring and management platform) - all versions before 2026.3 affected by CVE-2026-18576
Apache Tomcat - affected by CVE-2026-34486 (incomplete fix for CVE-2026-29146)

Related links:

Related CVE's:

Related threat actors:

IOC's:

Reverse shells planted on Apache Tomcat servers (reported by Palo Alto Networks Unit 42)

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page