Skip to content
live markets
S&P 5007,738.90▲ 3.42%NASDAQ26,448.86▲ 2.39%DOW54,571.65▲ 3.16%GOLD4,309.30▲ 3.71%WTI74.61▲ 8.84%BRENT78.85▲ 9.53%EUR/USD1.1558▲ 1.18%USD/JPY157.68▼ 2.33%DXY99.68▼ 1.16%BTC$64,714▲ 1.10%ETH$1,915▲ 2.30%SOL$74.48▲ 0.90%TOTAL CRYPTO$2.29T▲ 1.06%
pulseofnations.
Wed, Aug 5 2026 — 18:01 UTC telegram ↗ bluesky ↗ Join the wire

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, Including Langflow RCE

CISA flagged critical vulnerabilities in Langflow, Apache Tomcat, and N-central as actively exploited, ordering federal agencies to patch within three weeks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild and giving federal agencies three weeks to apply fixes.

The most severe is CVE-2026-9198, a code injection vulnerability in Langflow, the open-source AI workflow builder, carrying a CVSS score of 9.8. The flaw allows unauthenticated attackers to achieve full remote code execution by sending crafted requests to the Langflow API endpoint, effectively taking over any exposed server without credentials.

Also flagged is a flaw in N-central, the remote monitoring and management platform used by managed service providers to oversee client infrastructure. The vulnerability, CVE-2026-18577, is an authentication bypass that grants remote administrative access to N-central servers and, by extension, to all customer systems managed through them. Vendor N-able acknowledged that its initial fix shipped on August 2 was incomplete, leaving earlier builds exposed.

The third addition is an Apache Tomcat vulnerability that, while scoring lower on the CVSS scale, affects a ubiquitous web server platform underpinning enterprise applications worldwide. CISA did not disclose specific victim organizations but noted that exploitation had been observed across both government and private-sector networks.

The KEV catalog requires all federal Civilian Executive Branch agencies to remediate listed vulnerabilities by the deadline set in each entry, typically two to three weeks. While the catalog does not mandate action for private companies, CISA strongly recommends that all organizations treat KEV entries as priority patches given confirmed in-the-wild exploitation.

The announcements come during a particularly active month for vulnerability disclosures. Researchers have documented a surge in supply-chain compromises, zero-day exploits targeting developer tooling, and phishing kits designed to bypass multi-factor authentication across major cloud platforms.

Security teams are advised to audit their Langflow, N-central, and Tomcat deployments immediately, check for indicators of compromise shared in vendor advisories, and prioritize network segmentation for any unpatched systems until fixes are applied.

The Hacker News – CISA Flags Langflow, Tomcat, and N-central Flaws
CISA Known Exploited Vulnerabilities Catalog

Sources: The Hacker News, CISA KEV Catalog, N-able Security Advisory.

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Visa to Buy Cybersecurity Firm BioCatch for $2.4 Billion Read →