top of page
perceptive_background_267k.jpg

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

Published:

5 August 2026 at 09:40:39

Alert date:

5 August 2026 at 11:07:41

Source:

thehackernews.com

Click to open the original link from this advisory

Zero-Day Vulnerabilities, Web Technologies, Enterprise Applications, Network Infrastructure

On August 5, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The most critical is CVE-2026-9198 (CVSS 9.8), a code injection flaw in Langflow that allows unauthenticated attackers to achieve full remote code execution. The catalog update also includes vulnerabilities affecting Apache Tomcat and N-central. These additions signal active in-the-wild exploitation, prompting federal agencies and organizations to prioritize patching. CISA's KEV catalog serves as an authoritative source for vulnerabilities requiring urgent remediation. The Langflow flaw is particularly severe given its unauthenticated attack vector and critical CVSS score.

Technical details

Mitigation steps:

Affected products:

Langflow
Apache Tomcat
N-central

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page