VYPR
advisoryPublished Aug 5, 2026· 1 source

CISA Flags Exploited Flaws in Langflow, N-able N-central, and Apache Tomcat

CISA has issued an alert regarding actively exploited vulnerabilities in Langflow, N-able N-central, and Apache Tomcat, urging immediate patching.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning, highlighting three distinct vulnerabilities that are currently being actively exploited by threat actors. The agency has added these flaws, affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat, to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by August 7th.

The most critical of these is CVE-2026-9198, a severe vulnerability in Langflow OSS with a CVSS score of 9.8. This flaw allows unauthenticated attackers to achieve remote code execution by chaining two specific API endpoints. IBM disclosed this vulnerability on July 17th, releasing patches for Langflow OSS version 1.10.1, and noted that all default deployments were susceptible. The exploit involves obtaining a superuser bearer token from an unauthenticated endpoint and then using it to submit malicious code to a code validation endpoint, effectively granting attackers broad control.

Following closely is CVE-2026-18556, an authentication bypass vulnerability in N-able N-central, carrying a CVSS score of 7.4. Threat actors have reportedly exploited this flaw as a zero-day to gain administrative access to systems managed by the remote monitoring and management (RMM) platform. N-able initially released a fix, but attackers managed to bypass it, leading to the issuance of a hotfix and a new CVE, CVE-2026-18577, for the patch bypass. Both CVEs are now on CISA's KEV list, underscoring the persistent threat to managed service providers and their clients.

The third vulnerability flagged by CISA is CVE-2026-34486, a bypass in Apache Tomcat's EncryptInterceptor, rated at 7.5 CVSS. This flaw, patched in April, was inadvertently introduced in March during a fix for a padding oracle issue. The change inadvertently shifted the encryption layer from a fail-closed to a fail-open state, creating a direct path for unauthenticated remote code execution across cluster members. On affected deployments, attacker-controlled code could be forwarded unmodified through the interceptor chain upon failed decryption.

Exploitation of CVE-2026-34486 has been linked to sophisticated threat actors. SOCRadar reported its use by a Chinese threat actor in attacks involving the Snowlight malware family. Palo Alto Networks further observed Chinese hackers leveraging this vulnerability in an AI-enabled autonomous hacking campaign, highlighting the evolving tactics of nation-state-backed groups.

The inclusion of these vulnerabilities in CISA's KEV catalog signifies a heightened risk and mandates immediate attention from organizations. The agency's directive, in line with Binding Operational Directive 26-04, requires federal agencies to implement necessary security measures by August 7th to mitigate the potential impact of these actively exploited flaws.

These advisories serve as a critical reminder for organizations to maintain robust vulnerability management programs, prioritize patching based on threat intelligence, and stay vigilant against emerging threats. The rapid exploitation of newly disclosed vulnerabilities, often within hours or days of their public release, necessitates swift response and proactive security measures.

Synthesized by Vypr AI