CISA Adds Three Vulnerabilities to KEV Catalog: Langflow, Tomcat and N-central Affected
CISA adds three actively exploited vulnerabilities to the KEV catalog, impacting Langflow, Apache Tomcat, and N-central. Patch immediately by August 7, 2026.
Illustrative image generated with AI
Active Exploitation of Four Vulnerabilities
On August 5, 2026, CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The affected products are Langflow, Apache Tomcat and N-able N-central.
The N-central incident also involves CVE-2026-18577, which was already listed in the catalog and is linked to an incomplete fix for an earlier vulnerability.
- CVE-2026-9198 – Langflow, CVSS 9.8: enables unauthenticated remote code execution in default configurations.
- CVE-2026-34486 – Apache Tomcat, CVSS 7.5: allows attackers to bypass the cryptographic protection provided by
EncryptInterceptor, exposing communications between cluster nodes. - CVE-2026-18556 – N-able N-central, CVSS 8.2: enables authentication bypass.
- CVE-2026-18577 – N-able N-central, CVSS 8.2: involves an incomplete fix for the preceding vulnerability.
Langflow and N-central Require Immediate Action
Langflow fixed CVE-2026-9198 in version 1.10.1, released in July 2026. No details have been disclosed about the exploitation methods.
For N-central, administrators must apply patches for both vulnerabilities. Installing only the initial fix may leave systems exposed to CVE-2026-18577.
Operational priorities include Internet-facing systems, followed by reviewing authentication logs and investigating anomalous administrative access.
Tomcat Targeted in Focused Campaigns
CVE-2026-34486 was exploited in an AI-assisted campaign attributed to a Chinese-speaking threat actor. The operation reportedly combined automated reconnaissance with manual activity and targeted more than 460 victims.
The same vulnerability also appeared in operations targeting government and commercial infrastructure across more than 100 countries, with the aim of deploying the SNOWLIGHT Linux loader.
Observed between late April and early June 2026, the campaign compromised 107 endpoints. Detected incidents included root-level takeovers of cPanel/WHM systems and Domain Admin-level compromises through ProxyShell.
The threat actor reportedly also exploited vulnerabilities in Citrix NetScaler, Marimo, IKE VPN and n8n. Incident response efforts should therefore include hunting for indicators associated with SNOWLIGHT, GoCobaltStrike, tunnels and C2/RAT payloads.
Fixed Versions and Deadlines
The recommended Apache Tomcat updates are:
- 11.0.21
- 10.1.54
- 9.0.117
Administrators should upgrade Langflow to version 1.10.1 or later, install the N-able fixes for CVE-2026-18556 and CVE-2026-18577, and verify that the latest patch is installed.
FCEB agencies must complete remediation by August 7, 2026.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-41940Critical9.8cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- CVE-2026-39987Critical9.8marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket
- CVE-2026-3055Critical9.8Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
- CVE-2026-33017Critical9.8Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker
- CVE-2026-9198Critical9.8IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
- CVE-2026-33824Critical9.8Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
- CVE-2026-18577High8.1An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
- CVE-2026-34486High7.5Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the i
- CVE-2026-18556High7.4Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
