U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-9198 (CVSS score of 9.8) IBM Langflow Code Injection Vulnerability
- CVE-2026-18556 (CVSS score of 8.2) N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
- CVE-2026-34486 (CVS score of 7.5) Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
The first issue added to the catalog, tracked as CVE-2026-9198, is a critical issue in IBM Langflow OSS versions 1.0.0–1.10.0 that lets unauthenticated attackers gain superuser access and execute arbitrary code, leading to full remote code execution on default deployments.
The second issue, tracked as CVE-2026-18556, is an authentication bypass flaw in N-able N-central that allows attackers to access affected systems without valid credentials, impacting versions through 2026.1.
The last issue added to the KeV catalog is CVE-2026-34486, a flaw in Apache Tomcat versions 11.0.20, 10.1.53, and 9.0.116 that can bypass the EncryptInterceptor, exposing sensitive data.
Researchers linked the exploitation of CVE-2026-34486 to a Chinese-speaking threat actor that used an AI-powered autonomous hacking agent based on DeepSeek to identify and exploit internet-facing vulnerabilities. When one attack path failed, the AI independently searched for alternative flaws, while the attackers also carried out manual exploitation of vulnerabilities in Citrix NetScaler, Apache Tomcat, Marimo, and IKE VPN systems.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaws by August 7, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
