Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

0
Critical
Vulnerabilityremoterce
Published: 08/05/2026 (08/05/2026, 09:44:50 UTC)
Source: SecurityWeek

Description

CISA has issued a warning about active exploitation of three critical vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities enable remote code execution, authentication bypass, and an EncryptInterceptor bypass. IBM Langflow OSS versions prior to 1.10.1 are affected by a flaw allowing unauthenticated attackers to chain API endpoints to execute arbitrary Python code. N-able N-central suffered an authentication bypass exploited as a zero-day, with an initial incomplete fix requiring a hotfix. Apache Tomcat's EncryptInterceptor bypass flaw, introduced in March and patched in April, allows unauthenticated remote code execution on cluster members. CISA urges federal agencies to patch these vulnerabilities promptly.

Affected software

Affected versions
*

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 09:56:25 UTC

Technical Analysis

The US Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of three vulnerabilities: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-18556 and CVE-2026-18577 in N-able N-central, and CVE-2026-34486 in Apache Tomcat. CVE-2026-9198 (CVSS 9.8) allows unauthenticated attackers to obtain superuser bearer tokens via an auto-login endpoint and then execute arbitrary Python code through a code validation endpoint. IBM patched this in Langflow OSS version 1.10.1. N-able N-central's CVE-2026-18556 (CVSS 7.4) is an authentication bypass exploited as a zero-day to gain administrative access; an initial patch was bypassed, prompting a hotfix CVE-2026-18577. Apache Tomcat's CVE-2026-34486 (CVSS 7.5) is an EncryptInterceptor bypass that turns the encryption layer from fail-closed to fail-open, enabling unauthenticated remote code execution on cluster members; this was patched in April following the introduction of a related padding oracle flaw CVE-2026-29146. These vulnerabilities are listed in CISA's Known Exploited Vulnerabilities catalog, with active exploitation observed, including by Chinese threat actors using malware such as Snowlight. CISA mandates patching by August 7, 2026.

Potential Impact

These vulnerabilities enable unauthenticated remote code execution and authentication bypass, allowing attackers to gain administrative or superuser access, execute arbitrary code, and potentially control affected systems. The Langflow OSS flaw allows attackers to chain API endpoints to obtain superuser tokens and execute Python code remotely. The N-able N-central vulnerabilities have been exploited to bypass authentication and gain administrative access to managed systems. The Apache Tomcat EncryptInterceptor bypass allows unauthenticated remote code execution on cluster members, undermining encryption protections. Exploitation has been observed in the wild, including by advanced threat actors deploying malware, posing significant risk to affected organizations.

Mitigation Recommendations

IBM has released Langflow OSS version 1.10.1 to address CVE-2026-9198; users should upgrade immediately. N-able issued a hotfix addressing CVE-2026-18556 and CVE-2026-18577; affected users must apply the hotfix to fully remediate the authentication bypass. Apache Tomcat patched CVE-2026-34486 in April; users should ensure they have applied the April patch to prevent EncryptInterceptor bypass exploitation. CISA urges all federal agencies and affected organizations to apply these patches by August 7, 2026. No vendor advisory indicates these vulnerabilities are already mitigated without patching; therefore, timely patching is critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.85,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/","fetched":true,"fetchedAt":"2026-08-05T09:56:11.351Z","wordCount":1164}

Threat ID: 6a7308bbbf8831d539b04fbb

Added to database: 08/05/2026, 09:56:11 UTC

Last enriched: 08/05/2026, 09:56:25 UTC

Last updated: 08/05/2026, 12:05:55 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses