CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

Federal Agencies Given Three Days to Mitigate Critical Vulnerabilities Exploited by Hackers

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies, alerting them to a trio of critical vulnerabilities being actively exploited by hackers. The flaws affect IBM’s Langflow visual framework for building AI agents, N-able’s remote monitoring and management platform N-central, and Apache Tomcat web server software.

The most severe vulnerability is tracked as CVE-2026-9198, a critical flaw in Langflow that allows an unauthenticated attacker to execute code remotely on default deployments. This bug has been rated 9.8 out of 10 for its severity and can be exploited by chaining two API endpoints to bypass login requirements. Multiple proof-of-concept exploits have emerged publicly, providing complete instructions on how to leverage the vulnerability.

CISA also warned about a second Langflow flaw (CVE-2026-0770), which was previously exploited in attacks to gain remote code execution with root privileges. The agency has issued alerts for both vulnerabilities and is urging federal agencies to apply available mitigations by the end of Friday, July 7th. However, it’s worth noting that the deadline was initially reported as August 5th, but CISA has confirmed that the correct date is indeed July 7th.

Another vulnerability affects N-central, an IT management platform used for remote monitoring and management. The flaw (CVE-2026-18576) allows attackers to hijack administrative accounts without authentication, although it was initially patched by the vendor. Unfortunately, the fix proved insufficient, and hackers have found a new way to exploit the issue. N-able has released an emergency hotfix to address the problem.

Additionally, CISA highlighted a vulnerability in Apache Tomcat (CVE-2026-34486) that stems from an incomplete fix for a previous critical flaw. Researchers at Palo Alto Networks Unit 42 reported observing attempts by a Chinese-speaking threat actor to exploit this vulnerability as part of a manual campaign to plant reverse shells on several servers.

The CISA warning is the latest in a string of alerts issued for actively exploited vulnerabilities, including those affecting Microsoft SharePoint and Joomla plugin software. The agency’s Known Exploited Vulnerabilities (KEV) catalog now includes these three flaws, indicating that hackers are leveraging them in attacks.

What does this mean for security teams? With 54% of successful attacks going undetected until they’ve already caused damage, it’s essential to stay one step ahead of potential threats. Regularly testing and updating systems can help prevent such vulnerabilities from being exploited.


Source: Bleeping Computer — 2026-08-05