


Perceptive Security
SOC/SIEM Consultancy

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Published:
5 August 2026 at 07:40:39
Alert date:
5 August 2026 at 09:07:41
Source:
thehackernews.com
Zero-Day Vulnerabilities, Web Technologies, Enterprise Applications, Network Infrastructure
On August 5, 2026, CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The most critical is CVE-2026-9198 (CVSS 9.8), a code injection flaw in Langflow that allows unauthenticated attackers to achieve full remote code execution. The catalog update also includes vulnerabilities affecting Apache Tomcat and N-central. These additions signal active in-the-wild exploitation, prompting federal agencies and organizations to prioritize patching. CISA's KEV catalog serves as an authoritative source for vulnerabilities requiring urgent remediation. The Langflow flaw is particularly severe given its unauthenticated attack vector and critical CVSS score.
Technical details
Mitigation steps:
Affected products:
Langflow
Apache Tomcat
N-central
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
