CISA flags Langflow, Tomcat, N-central
- CISA on August 4 added Langflow, Apache Tomcat and N-able N-central flaws to its exploited-vulnerability catalog, citing evidence of active attacks. - The most concrete detail is CISA’s August 7 remediation deadline for federal agencies on the newly added Langflow, Tomcat and N-central entries. - N-able says partners should upgrade to 2026.3.1.7, while CISA’s KEV catalog lists required action dates and affected CVEs.
CISA added three software flaws to its Known Exploited Vulnerabilities catalog on August 4 and said all three are being used in attacks. The entries cover CVE-2026-9198 in IBM Langflow, CVE-2026-34486 in Apache Tomcat and CVE-2026-18556 in N-able N-central, according to the agency’s alert and KEV catalog. Federal agencies are required to act on the additions under Binding Operational Directive 26-04, and CISA said other organizations should also prioritize remediation. ### Which flaws did CISA add, exactly? CISA’s August 4 alert named CVE-2026-9198 as an IBM Langflow code-injection vulnerability, CVE-2026-18556 as an N-able N-central authentication-bypass flaw, and CVE-2026-34486 as an Apache Tomcat vulnerability involving missing encryption of sensitive data. The agency said the vulnerabilities were added “based on evidence of active exploitation.” (cisa.gov) The KEV catalog entry for Tomcat says CVE-2026-34486 allows bypass of the EncryptInterceptor. NVD says the issue affects Apache Tomcat 11.0.20, 10.1.53 and 9.0.116, and recommends upgrading to 11.0.21, 10.1.54 or 9.0.117. ### Why does Langflow stand out in this batch? NVD describes Langflow as a tool for building and deploying AI-powered agents and workflows. CISA had already added a different Langflow flaw, CVE-2026-33017, to the KEV catalog on March 25, showing the product had appeared before in the agency’s exploited-vulnerability list. (cisa.gov) Unit 42 said in a report published six days ago that it identified an AI-enabled autonomous hacking campaign by a Chinese-speaking threat actor that used DeepSeek through the Hermes Agent framework. (cisa.gov) The researchers said the operation combined autonomous AI-driven enumeration with manual exploitation across seven vulnerabilities and achieved confirmed impact. Unit 42’s report does not, in the search result available here, state that the campaign was limited to one of CISA’s August 4 additions, but it does tie DeepSeek to real-world offensive activity. (nvd.nist.gov) ### What is happening with N-able N-central? N-able said in an August 4 security update that its upgrade covers CVE-2026-18577 and CVE-2026-18556. The company said an attacker had identified a vulnerability on all N-central servers running a version prior to 2026.3.1.7 that allowed remote administrative access. N-able’s status page says all N-central instances not running 2026.3 were affected by CVE-2026-18577 and that a 2026.3.1.7 hotfix had been released. (unit42.paloaltonetworks.com) The company said partners should upgrade “ASAP.” ### Why are banks and other large enterprises paying attention to “adjacent” tools? CISA says the KEV catalog is meant to help organizations manage vulnerabilities that are known to be exploited in the wild. (n-able.com) That matters because the products in this week’s additions are not limited to customer-facing banking systems; they can also appear in developer tooling, middleware and remote-management environments. (status.n-able.com) Apache Tomcat remains common Java middleware, N-central is a management platform, and Langflow is used to build AI workflows. When those systems sit in management or development planes, they can provide access paths into broader environments if left exposed or unpatched, according to the product descriptions and vendor advisories. ### What happens next? CISA’s KEV catalog lists August 7, 2026, as the action due date for the Tomcat entry added on August 4. (cisa.gov) The agency’s alert says federal civilian agencies must prioritize remediation under BOD 26-04, and it encourages all organizations to use the KEV list in risk-based patching. N-able, for its part, is directing customers to 2026.3.1.7, while Apache points users to fixed Tomcat releases in its security advisories. (langflow.org)