Particle.news

CISA Adds Langflow, Apache Tomcat and N‑able Flaws to Known Exploited Vulnerabilities

The agency is forcing federal agencies to install vendor fixes by August 7 to stop active attacks that security firms link to an AI‑enabled Chinese‑speaking threat actor.

Overview

  • CISA added CVE‑2026‑9198 (Langflow), CVE‑2026‑34486 (Apache Tomcat) and CVE‑2026‑18556/18577 (N‑able N‑central) to its KEV catalog on Wednesday, signaling observed in‑the‑wild exploitation.
  • Langflow’s bug lets unauthenticated callers get a superuser token and run arbitrary Python code and was patched in version 1.10.1 on July 17 after proof‑of‑concept code appeared.
  • Apache Tomcat’s CVE‑2026‑34486 stems from an EncryptInterceptor change patched in April that can forward attacker data to deserialization and give unauthenticated remote code execution on cluster members.
  • N‑able’s N‑central suffered an authentication bypass zero‑day that was exploited for admin access, the vendor’s initial fix was bypassed and a hotfix was issued as CVE‑2026‑18577.
  • Federal civilian agencies must apply mitigations under BOD 26‑04 by August 7 and private operators are urged to patch now because researchers say the attacks use an AI autonomous agent to scale reconnaissance and exploitation, increasing the speed and reach of intrusions.