CISA Identifies Critical Vulnerabilities in Langflow, Tomcat, and N-central as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting their active exploitation. These vulnerabilities include a code injection flaw in Langflow (CVE-2026-9198) with a CVSS score of 9.8, which allows unauthenticated attackers to execute remote code. This issue was addressed in July 2026 with version 1.10.1. Another vulnerability, CVE-2026-34486, affects Apache Tomcat, allowing a bypass of encryption mechanisms, and was fixed in April 2026. The third, CVE-2026-18556, is an authentication bypass in N-able N-central, which required a subsequent patch due to an incomplete initial fix. These vulnerabilities are being exploited by threat actors, including a Chinese-speaking group using AI-enabled hacking campaigns. The exploitation of these flaws poses significant risks to internet-exposed devices and infrastructure.