CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
CISA has issued a warning about active exploitation of three critical vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities enable remote code execution, authentication bypass, and an EncryptInterceptor bypass. IBM Langflow OSS versions prior to 1.10.1 are affected by a flaw allowing unauthenticated attackers to chain API endpoints to execute arbitrary Python code. N-able N-central suffered an authentication bypass exploited as a zero-day, with an initial incomplete fix requiring a hotfix. Apache Tomcat's EncryptInterceptor bypass flaw, introduced in March and patched in April, allows unauthenticated remote code execution on cluster members. CISA urges federal agencies to patch these vulnerabilities promptly.
AI Analysis
Technical Summary
The US Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of three vulnerabilities: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-18556 and CVE-2026-18577 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. CVE-2026-9198 (CVSS 9.8) allows unauthenticated attackers to obtain superuser bearer tokens via an auto-login endpoint and then execute arbitrary Python code through a code validation endpoint. IBM patched this in Langflow OSS version 1.10.1. N-able N-central's CVE-2026-18556 (CVSS 7.4) is an authentication bypass exploited as a zero-day to gain administrative access; an initial patch was bypassed, prompting a hotfix CVE-2026-18577. Apache Tomcat's CVE-2026-34486 (CVSS 7.5) is an EncryptInterceptor bypass that turns the encryption layer from fail-closed to fail-open, enabling unauthenticated remote code execution on cluster members; this was patched in April following the introduction of a related padding oracle flaw CVE-2026-29146. These vulnerabilities are listed in CISA's Known Exploited Vulnerabilities catalog, with active exploitation observed, including by Chinese threat actors using malware such as Snowlight. CISA mandates patching by August 7, 2026.
Potential Impact
These vulnerabilities enable unauthenticated remote code execution and authentication bypass, allowing attackers to gain administrative or superuser access, execute arbitrary code, and potentially control affected systems. The Langflow OSS flaw allows attackers to chain API endpoints to obtain superuser tokens and execute Python code remotely. The N-able N-central vulnerabilities have been exploited to bypass authentication and gain administrative access to managed systems. The Apache Tomcat EncryptInterceptor bypass allows unauthenticated remote code execution on cluster members, undermining encryption protections. Exploitation has been observed in the wild, including by advanced threat actors deploying malware, posing significant risk to affected organizations.
Mitigation Recommendations
IBM has released Langflow OSS version 1.10.1 to address CVE-2026-9198; users should upgrade immediately. N-able issued a hotfix addressing CVE-2026-18556 and CVE-2026-18577; affected users must apply the hotfix to fully remediate the authentication bypass. Apache Tomcat patched CVE-2026-34486 in April; users should ensure they have applied the April patch to prevent EncryptInterceptor bypass exploitation. CISA urges all federal agencies and affected organizations to apply these patches by August 7, 2026. No vendor advisory indicates these vulnerabilities are already mitigated without patching; therefore, timely patching is critical.
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
Description
CISA has issued a warning about active exploitation of three critical vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities enable remote code execution, authentication bypass, and an EncryptInterceptor bypass. IBM Langflow OSS versions prior to 1.10.1 are affected by a flaw allowing unauthenticated attackers to chain API endpoints to execute arbitrary Python code. N-able N-central suffered an authentication bypass exploited as a zero-day, with an initial incomplete fix requiring a hotfix. Apache Tomcat's EncryptInterceptor bypass flaw, introduced in March and patched in April, allows unauthenticated remote code execution on cluster members. CISA urges federal agencies to patch these vulnerabilities promptly.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The US Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of three vulnerabilities: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-18556 and CVE-2026-18577 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. CVE-2026-9198 (CVSS 9.8) allows unauthenticated attackers to obtain superuser bearer tokens via an auto-login endpoint and then execute arbitrary Python code through a code validation endpoint. IBM patched this in Langflow OSS version 1.10.1. N-able N-central's CVE-2026-18556 (CVSS 7.4) is an authentication bypass exploited as a zero-day to gain administrative access; an initial patch was bypassed, prompting a hotfix CVE-2026-18577. Apache Tomcat's CVE-2026-34486 (CVSS 7.5) is an EncryptInterceptor bypass that turns the encryption layer from fail-closed to fail-open, enabling unauthenticated remote code execution on cluster members; this was patched in April following the introduction of a related padding oracle flaw CVE-2026-29146. These vulnerabilities are listed in CISA's Known Exploited Vulnerabilities catalog, with active exploitation observed, including by Chinese threat actors using malware such as Snowlight. CISA mandates patching by August 7, 2026.
Potential Impact
These vulnerabilities enable unauthenticated remote code execution and authentication bypass, allowing attackers to gain administrative or superuser access, execute arbitrary code, and potentially control affected systems. The Langflow OSS flaw allows attackers to chain API endpoints to obtain superuser tokens and execute Python code remotely. The N-able N-central vulnerabilities have been exploited to bypass authentication and gain administrative access to managed systems. The Apache Tomcat EncryptInterceptor bypass allows unauthenticated remote code execution on cluster members, undermining encryption protections. Exploitation has been observed in the wild, including by advanced threat actors deploying malware, posing significant risk to affected organizations.
Mitigation Recommendations
IBM has released Langflow OSS version 1.10.1 to address CVE-2026-9198; users should upgrade immediately. N-able issued a hotfix addressing CVE-2026-18556 and CVE-2026-18577; affected users must apply the hotfix to fully remediate the authentication bypass. Apache Tomcat patched CVE-2026-34486 in April; users should ensure they have applied the April patch to prevent EncryptInterceptor bypass exploitation. CISA urges all federal agencies and affected organizations to apply these patches by August 7, 2026. No vendor advisory indicates these vulnerabilities are already mitigated without patching; therefore, timely patching is critical.
Technical Details
- Classification
- {"confidence":0.85,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/","fetched":true,"fetchedAt":"2026-08-05T09:56:11.351Z","wordCount":1164}
Threat ID: 6a7308bbbf8831d539b04fbb
Added to database: 08/05/2026, 09:56:11 UTC
Last enriched: 08/05/2026, 09:56:25 UTC
Last updated: 08/05/2026, 12:05:55 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.