CISA Adds Three Vulnerabilities to KEV Catalog: Langflow, Tomcat and N-central Affected

CISA adds three actively exploited vulnerabilities to the KEV catalog, impacting Langflow, Apache Tomcat, and N-central. Patch immediately by August 7, 2026.

CISA Adds Three Vulnerabilities to KEV Catalog: Langflow, Tomcat and N-central Affected
Vulnerabilities

Illustrative image generated with AI

Active Exploitation of Four Vulnerabilities

On August 5, 2026, CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The affected products are Langflow, Apache Tomcat and N-able N-central.

The N-central incident also involves CVE-2026-18577, which was already listed in the catalog and is linked to an incomplete fix for an earlier vulnerability.

  • CVE-2026-9198 – Langflow, CVSS 9.8: enables unauthenticated remote code execution in default configurations.
  • CVE-2026-34486 – Apache Tomcat, CVSS 7.5: allows attackers to bypass the cryptographic protection provided by EncryptInterceptor, exposing communications between cluster nodes.
  • CVE-2026-18556 – N-able N-central, CVSS 8.2: enables authentication bypass.
  • CVE-2026-18577 – N-able N-central, CVSS 8.2: involves an incomplete fix for the preceding vulnerability.

Langflow and N-central Require Immediate Action

Langflow fixed CVE-2026-9198 in version 1.10.1, released in July 2026. No details have been disclosed about the exploitation methods.

For N-central, administrators must apply patches for both vulnerabilities. Installing only the initial fix may leave systems exposed to CVE-2026-18577.

Operational priorities include Internet-facing systems, followed by reviewing authentication logs and investigating anomalous administrative access.

Tomcat Targeted in Focused Campaigns

CVE-2026-34486 was exploited in an AI-assisted campaign attributed to a Chinese-speaking threat actor. The operation reportedly combined automated reconnaissance with manual activity and targeted more than 460 victims.

The same vulnerability also appeared in operations targeting government and commercial infrastructure across more than 100 countries, with the aim of deploying the SNOWLIGHT Linux loader.

Observed between late April and early June 2026, the campaign compromised 107 endpoints. Detected incidents included root-level takeovers of cPanel/WHM systems and Domain Admin-level compromises through ProxyShell.

The threat actor reportedly also exploited vulnerabilities in Citrix NetScaler, Marimo, IKE VPN and n8n. Incident response efforts should therefore include hunting for indicators associated with SNOWLIGHT, GoCobaltStrike, tunnels and C2/RAT payloads.

Fixed Versions and Deadlines

The recommended Apache Tomcat updates are:

  • 11.0.21
  • 10.1.54
  • 9.0.117

Administrators should upgrade Langflow to version 1.10.1 or later, install the N-able fixes for CVE-2026-18556 and CVE-2026-18577, and verify that the latest patch is installed.

FCEB agencies must complete remediation by August 7, 2026.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsCISAKEVLangflowApache TomcatN-centralvulnerabilitiesexploitationremediation
Back to home