The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are exploiting critical vulnerabilities in three widely used software products, including IBM’s Langflow visual framework for building AI agents. The agency is urging federal agencies to take immediate action to mitigate these flaws, which have already been actively exploited by attackers.
The most severe vulnerability, tracked as CVE-2026-9198, affects Langflow and allows an unauthenticated attacker to execute code remotely on default deployments. This means that a hacker can bypass login requirements and run malicious code on the affected system without needing any credentials. The flaw has a critical rating of 9.8 out of 10, making it one of the most severe vulnerabilities discovered this year.
In addition to Langflow, CISA is also warning about vulnerabilities in N-able’s remote monitoring and management platform N-central (CVE-2026-18576) and Apache Tomcat (CVE-2026-34486). The N-central flaw allows attackers to hijack administrative accounts without authentication, while the Apache Tomcat vulnerability stems from an incomplete fix for a previous critical flaw. Both of these vulnerabilities have been patched by their respective vendors, but the fixes have proven insufficient, and threat actors have found new ways to exploit them.
The Apache Tomcat vulnerability is particularly concerning because it has already been exploited in a manual campaign by a Chinese-speaking threat actor, who attempted to plant reverse shells on nine servers. CISA has confirmed that attackers are leveraging all three flaws in attacks, although the agency did not provide details on the types of attacks being used or whether they are part of ransomware campaigns.
The warning from CISA comes after multiple proof-of-concept exploits for the Langflow vulnerability emerged in the public space, complete with instructions on how to use them. This means that hackers may soon have easy-to-use tools at their disposal to exploit these vulnerabilities and gain unauthorized access to affected systems.
In light of this warning, it’s essential for security teams to take immediate action to mitigate these flaws. CISA has ordered federal agencies to apply available mitigations for the three targeted products by the end of Friday, July 7th. For all users of these software products, it’s crucial to stay vigilant and take steps to protect themselves from potential attacks.
As a practical takeaway, we recommend that organizations test their systems thoroughly before attackers do. Regular breach and attack simulation tests can help identify vulnerabilities and ensure that security teams are prepared to respond quickly in the event of an attack. By staying one step ahead of hackers, you can reduce your organization’s risk of falling victim to these exploited vulnerabilities.
Source: Bleeping Computer — 2026-08-05