Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited: A Growing Threat Landscape



CISA has flagged three flaws as actively exploited in the wild, including CVE-2026-9198, CVE-2026-34486, and CVE-2026-18556. Organizations must take proactive measures to protect themselves against these vulnerabilities, including timely patching and vulnerability management. By staying informed about emerging threats and strengthening their security posture, organizations can reduce their risk of falling prey to active threats.

  • CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
  • CVE-2026-9198, CVE-2026-34486, and CVE-2026-18556 pose significant security risks if left unpatched.
  • CVE-2026-9198 allows full remote code execution on default Langflow deployments.
  • CVE-2026-34486 bypasses encryption of sensitive data in Apache Tomcat.
  • CVE-2026-18556 is an authentication bypass vulnerability in N-able N-central.
  • Threat actors are actively exploiting these vulnerabilities, highlighting the importance of timely patching and vulnerability management.



  • In a recent announcement from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), three flaws have been added to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities includes CVE-2026-9198, CVE-2026-34486, and CVE-2026-18556, which pose significant security risks to organizations that fail to apply timely patches.

    CVE-2026-9198 is a code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. This particular flaw has already been identified as a target of malicious actors, who have weaponized security defects in the open-source artificial intelligence (AI) application development platform in recent months. The exploitation of this vulnerability has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.

    CVE-2026-34486, on the other hand, is a missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. This flaw has also been identified as being exploited by threat actors, who have leveraged DeepSeek via the Hermes Agent framework as an offensive operator to target internet-exposed devices.

    In addition to CVE-2026-9198 and CVE-2026-34486, CVE-2026-18556 is an authentication bypass vulnerability in N-able N-central that has also been found to be actively exploited. It's worth noting that an incomplete fix for this issue prompted N-able to issue a fresh patch, which is tracked as CVE-2026-18577 (CVSS score: 8.2). Despite the availability of these patches, threat actors continue to exploit both vulnerabilities, highlighting the ongoing threat landscape in cybersecurity.

    The exploitation of these flaws by threat actors demonstrates the importance of timely patching and vulnerability management. Organizations that fail to apply necessary security updates risk falling prey to active threats, which can have significant consequences for their networks and data. In light of this recent announcement from CISA, it is essential for organizations to take proactive measures to protect themselves against these actively exploited vulnerabilities.

    Furthermore, the use of AI-enabled autonomous hacking campaigns highlights the growing role of artificial intelligence in cybersecurity threats. The ability of threat actors to leverage advanced technologies such as DeepSeek and Hermes Agent to target vulnerabilities has significant implications for the security posture of organizations. As AI-powered attacks continue to evolve, it is crucial for organizations to stay informed about emerging threats and take steps to protect themselves against these types of attacks.

    In conclusion, the recent announcement from CISA regarding the addition of CVE-2026-9198, CVE-2026-34486, and CVE-2026-18556 to its KEV catalog serves as a stark reminder of the ongoing threat landscape in cybersecurity. Organizations must take proactive measures to protect themselves against these actively exploited vulnerabilities, including timely patching and vulnerability management. By staying informed about emerging threats and taking steps to strengthen their security posture, organizations can reduce their risk of falling prey to active threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISA-Flags-Langflow-RCE-Tomcat-and-N-central-Flaws-as-Actively-Exploited-A-Growing-Threat-Landscape-ehn.shtml

  • https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html

  • https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-9198

  • https://www.cvedetails.com/cve/CVE-2026-9198/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-34486

  • https://www.cvedetails.com/cve/CVE-2026-34486/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-18556

  • https://www.cvedetails.com/cve/CVE-2026-18556/


  • Published: Wed Aug 5 04:00:16 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us