Overview
- CISA added CVE‑2026‑9198 (Langflow), CVE‑2026‑34486 (Apache Tomcat) and CVE‑2026‑18556/18577 (N‑able N‑central) to its KEV catalog on Wednesday, signaling observed in‑the‑wild exploitation.
- Langflow’s bug lets unauthenticated callers get a superuser token and run arbitrary Python code and was patched in version 1.10.1 on July 17 after proof‑of‑concept code appeared.
- Apache Tomcat’s CVE‑2026‑34486 stems from an EncryptInterceptor change patched in April that can forward attacker data to deserialization and give unauthenticated remote code execution on cluster members.
- N‑able’s N‑central suffered an authentication bypass zero‑day that was exploited for admin access, the vendor’s initial fix was bypassed and a hotfix was issued as CVE‑2026‑18577.
- Federal civilian agencies must apply mitigations under BOD 26‑04 by August 7 and private operators are urged to patch now because researchers say the attacks use an AI autonomous agent to scale reconnaissance and exploitation, increasing the speed and reach of intrusions.