CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
Article Content
- •CISA added critical vulnerabilities to its KEV catalog, requiring urgent patches.
- •The Tomcat flaw is exploited by a Chinese-speaking actor using AI techniques.
- •Federal agencies have a deadline of August 7, 2026, to apply necessary fixes.
CISA has added critical vulnerabilities in IBM Langflow, Apache Tomcat, and N-able N-central to its Known Exploited Vulnerabilities catalog, with a deadline for federal agencies to patch by August 7, 2026. The Langflow flaw (CVE-2026-9198) allows remote code execution, while the Tomcat flaw (CVE-2026-34486) enables an EncryptInterceptor bypass. Both vulnerabilities are being actively exploited, with the Tomcat flaw linked to a Chinese-speaking actor using AI-driven techniques to target over 460 systems. The N-central flaw involves an authentication bypass that has been previously patched but exploited again. Organizations using these products are urged to apply fixes immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ransom Cartel, Knaithe and Emotet in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Operation Alice: Massive Dark Web Takedown of 373,000 Fraudulent Sites Between March 9 and March 19, 2026, law enforcement from 23 countries dismantled a vast network of 373,000 dark web sites operated by a single individual. This operation, known as Operation Alice, was led by German authorities and supported by Europol. The operator, a 35-year-old man from China, ran these fraudulent…